category: Endpoint provider: CrowdStrike sectionorder: - Connect - Collect commonfields: id: CrowdStrike OpenAPI version: -1 configuration: - defaultvalue: https://api.crowdstrike.com display: Cloud Base URL name: server_url required: true section: Connect type: 15 options: - https://api.crowdstrike.com - https://api.laggar.gcw.crowdstrike.com - https://api.eu-1.crowdstrike.com - https://api.us-2.crowdstrike.com - display: Client ID displaypassword: Client Secret name: credentials section: Connect required: true type: 9 - display: The amount of time (in seconds) that a request will wait for a client to establish a connection to a remote machine before a timeout occurs. name: timeout section: Connect defaultvalue: "10" type: 0 required: false - display: Use system proxy settings name: proxy type: 8 section: Connect required: false - display: Trust any certificate (not secure) name: insecure section: Connect type: 8 required: false description: Use the CrowdStrike OpenAPI integration to interact with CrowdStrike APIs that do not have dedicated integrations in Cortex XSOAR, for example, CrowdStrike FalconX, etc. display: CrowdStrike OpenAPI (Beta) name: CrowdStrike OpenAPI script: commands: - arguments: - description: '' isArray: true name: domain_mssprolerequestv1_resources required: true description: 'Assign new MSSP Role(s) between User Group and CID Group. It does not revoke existing role(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request. ' name: cs-add-role outputs: - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.user_group_id description: '' type: String - arguments: - description: '' isArray: true name: domain_usergroupmembersrequestv1_resources required: true description: Add new User Group member. Maximum 500 members allowed per User Group. name: cs-add-user-group-members outputs: - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.resources.user_group_id description: '' type: String - arguments: - description: '' isArray: true name: domain_cidgroupmembersrequestv1_resources required: true description: Add new CID Group member. name: cs-addcid-group-members outputs: - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.resources.cid_group_id description: '' type: String - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate allowlist ticket values based on the matched filter. name: cs-aggregate-allow-list outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate block list ticket values based on the matched filter. name: cs-aggregate-block-list outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate detection values based on the matched filter. name: cs-aggregate-detections outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate host/devices count based on the matched filter. name: cs-aggregate-device-count-collection outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate escalation ticket values based on the matched filter. name: cs-aggregate-escalations outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get notification aggregates as specified via JSON in request body. name: cs-aggregate-notificationsv1 outputs: - contextPath: CrowdStrike.domainAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate remediation ticket values based on the matched filter. name: cs-aggregate-remediations outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_date_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_field required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_filter required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_interval required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_missing required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_name required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_size required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_time_zone required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_type required: true description: Aggregate events for customer. name: cs-aggregateevents outputs: - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Retrieve aggregate incident values based on the matched filter. name: cs-aggregatefc-incidents outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_date_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_field required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_filter required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_interval required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_missing required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_name required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_size required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_time_zone required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_type required: true description: Aggregate rules within a policy for customer. name: cs-aggregatepolicyrules outputs: - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_date_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_field required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_filter required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_interval required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_missing required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_name required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_size required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_time_zone required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_type required: true description: Aggregate rule groups for customer. name: cs-aggregaterulegroups outputs: - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_date_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_field required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_filter required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_interval required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_missing required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_name required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_ranges required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_size required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: fwmgr_msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_time_zone required: true - description: '' name: fwmgr_msa_aggregatequeryrequest_type required: true description: Aggregate rules for customer. name: cs-aggregaterules outputs: - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: An FQL filter string. name: filter_ required: true description: Get the total number of detections pushed across all customers. name: cs-aggregates-detections-global-counts outputs: - contextPath: CrowdStrike.msaFacetsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.count description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.resources.facet description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.label description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.term description: '' type: String - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get aggregate OverWatch detection event info by providing an aggregate query. name: cs-aggregates-events outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get OverWatch detection event collection info by providing an aggregate query. name: cs-aggregates-events-collections outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: An FQL filter string. name: filter_ required: true description: Get the total number of incidents pushed across all customers. name: cs-aggregates-incidents-global-counts outputs: - contextPath: CrowdStrike.msaFacetsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.count description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.resources.facet description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.label description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.term description: '' type: String - arguments: - description: An FQL filter string. name: filter_ required: true description: Get the total number of OverWatch events across all customers. name: cs-aggregatesow-events-global-counts outputs: - contextPath: CrowdStrike.msaFacetsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.count description: '' type: Number - contextPath: CrowdStrike.msaFacetsResponse.resources.facet description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.label description: '' type: String - contextPath: CrowdStrike.msaFacetsResponse.resources.term description: '' type: String - arguments: - description: Authorization Header. name: Authorization required: true description: Identity Protection GraphQL API. Allows to retrieve entities, timeline activities, identity-based incidents and security assessment. Allows to perform actions on entities and identity-based incidents. name: cs-apipreemptproxypostgraphql - arguments: - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-1000]. Defaults to 50. name: limit - description: The property to sort by (e.g. timestamp.desc). name: sort - description: The filter expression that should be used to limit the results (e.g., `action:'token_create'`). name: filter_ description: Search for audit events by providing an FQL filter and paging details. name: cs-auditeventsquery outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: IDs of audit events to retrieve details for. isArray: true name: ids description: Gets the details of one or more audit events by id. name: cs-auditeventsread outputs: - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.actor description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.timestamp description: '' type: String - contextPath: CrowdStrike.apiauditEventDetailsResponseV1.resources.token_id description: '' type: String - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchexecutecommandrequest_base_command required: true - description: '' name: domain_batchexecutecommandrequest_batch_id required: true - description: '' name: domain_batchexecutecommandrequest_command_string required: true - description: '' isArray: true name: domain_batchexecutecommandrequest_optional_hosts - description: '' name: domain_batchexecutecommandrequest_persist_all required: true description: Batch executes a RTR active-responder command across the hosts mapped to the given batch ID. name: cs-batch-active-responder-cmd - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchexecutecommandrequest_base_command required: true - description: '' name: domain_batchexecutecommandrequest_batch_id required: true - description: '' name: domain_batchexecutecommandrequest_command_string required: true - description: '' isArray: true name: domain_batchexecutecommandrequest_optional_hosts - description: '' name: domain_batchexecutecommandrequest_persist_all required: true description: Batch executes a RTR administrator command across the hosts mapped to the given batch ID. name: cs-batch-admin-cmd - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchexecutecommandrequest_base_command required: true - description: '' name: domain_batchexecutecommandrequest_batch_id required: true - description: '' name: domain_batchexecutecommandrequest_command_string required: true - description: '' isArray: true name: domain_batchexecutecommandrequest_optional_hosts - description: '' name: domain_batchexecutecommandrequest_persist_all required: true description: Batch executes a RTR read-only command across the hosts mapped to the given batch ID. name: cs-batch-cmd - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchgetcommandrequest_batch_id required: true - description: '' name: domain_batchgetcommandrequest_file_path required: true - description: '' isArray: true name: domain_batchgetcommandrequest_optional_hosts description: Batch executes `get` command across hosts to retrieve files. After this call is made `GET /real-time-response/combined/batch-get-command/v1` is used to query for the results. name: cs-batch-get-cmd - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: Batch Get Command Request ID received from `/real-time-response/combined/get-command/v1`. name: batch_get_cmd_req_id required: true description: Retrieves the status of the specified batch get command. Will return successful files when they are finished processing. name: cs-batch-get-cmd-status outputs: - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.size description: '' type: Number - contextPath: CrowdStrike.domainBatchGetCmdStatusResponse.resources.updated_at description: '' type: String - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchinitsessionrequest_existing_batch_id - description: '' isArray: true name: domain_batchinitsessionrequest_host_ids required: true - description: '' name: domain_batchinitsessionrequest_queue_offline required: true description: Batch initialize a RTR session on multiple hosts. Before any RTR commands can be used, an active session is needed on the host. name: cs-batch-init-sessions - arguments: - description: Timeout for how long to wait for the request in seconds, default timeout is 30 seconds. Maximum is 10 minutes. name: timeout - description: 'Timeout duration for for how long to wait for the request in duration syntax. Example, `10s`. Valid units: `ns, us, ms, s, m, h`. Maximum is 10 minutes.' name: timeout_duration - description: '' name: domain_batchrefreshsessionrequest_batch_id required: true - description: '' isArray: true name: domain_batchrefreshsessionrequest_hosts_to_remove required: true description: Batch refresh a RTR session on multiple hosts. RTR sessions will expire after 10 minutes unless refreshed. name: cs-batch-refresh-sessions - arguments: - description: '' isArray: true name: domain_registeractionsrequest_actions required: true - description: '' name: domain_registeractionsrequest_rule_id required: true description: Create actions for a monitoring rule. Accepts a list of actions that will be attached to the monitoring rule. name: cs-create-actionsv1 outputs: - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.cid description: The ID of the customer who created the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.created_timestamp description: The date when the action was created. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.frequency description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.id description: The ID of the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.rule_id description: The ID of the rule on which this action is attached. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.status description: The action status. It can be either 'enabled' or 'muted'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.type description: The action type. The only type currently supported is 'email'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.updated_timestamp description: The date when the action was updated. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.user_uuid description: The UUID of the user who created the action. type: String - arguments: - description: A collection of policies to create. isArray: true name: requests_createdevicecontrolpoliciesv1_resources required: true description: Create Device Control Policies by specifying details about the policy to create. name: cs-create-device-control-policies - arguments: - description: A collection of policies to create. isArray: true name: requests_createfirewallpoliciesv1_resources required: true - description: The policy ID to be cloned from. name: clone_id description: Create Firewall Policies by specifying details about the policy to create. name: cs-create-firewall-policies - arguments: - description: A collection of device groups to create. isArray: true name: requests_creategroupsv1_resources required: true description: Create Host Groups by specifying details about the group to create. name: cs-create-host-groups - arguments: - description: '' isArray: true name: models_modifyawscustomersettingsv1_resources required: true description: Create or update Global Settings which are applicable to all provisioned AWS accounts. name: cs-create-or-updateaws-settings - arguments: - description: A collection of policies to create. isArray: true name: requests_createpreventionpoliciesv1_resources required: true description: Create Prevention Policies by specifying details about the policy to create. name: cs-create-prevention-policies - arguments: - description: User UUID. name: X_CS_USERUUID - description: The filter to be used for searching. name: sadomain_createrulerequestv1_filter required: true - description: The name of a particular rule. name: sadomain_createrulerequestv1_name required: true - description: 'The permissions for a particular rule which specifies the rule''s access by other users. Possible values: [public private].' name: sadomain_createrulerequestv1_permissions required: true - description: 'The priority for a particular rule. Possible values: [medium high low].' name: sadomain_createrulerequestv1_priority required: true - description: 'The topic of a given rule. Possible values: [SA_THIRD_PARTY SA_CVE SA_ALIAS SA_AUTHOR SA_BRAND_PRODUCT SA_VIP SA_IP SA_BIN SA_DOMAIN SA_EMAIL SA_CUSTOM].' name: sadomain_createrulerequestv1_topic required: true description: Create monitoring rules. name: cs-create-rulesv1 outputs: - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.created_timestamp description: The creation time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.filter description: The FQL filter contained in a rule and used for searching. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.id description: The ID of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.name description: The name for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.permissions description: The permissions of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.priority description: The priority of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status description: The status of a rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status_message description: The detailed status message. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.topic description: The topic of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.updated_timestamp description: The last updated time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_id description: The user ID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_name description: The user name of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_uuid description: The UUID of the user that created a given rule. type: String - arguments: - description: A collection of policies to create. isArray: true name: requests_createsensorupdatepoliciesv1_resources required: true description: Create Sensor Update Policies by specifying details about the policy to create. name: cs-create-sensor-update-policies - arguments: - description: A collection of policies to create. isArray: true name: requests_createsensorupdatepoliciesv2_resources required: true description: Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection. name: cs-create-sensor-update-policiesv2 - arguments: - description: '' name: domain_usercreaterequest_firstname - description: '' name: domain_usercreaterequest_lastname - description: '' name: domain_usercreaterequest_password - description: '' name: domain_usercreaterequest_uid description: Create a new user. After creating a user, assign one or more roles with POST /user-roles/entities/user-roles/v1. name: cs-create-user - arguments: - description: '' isArray: true name: domain_usergroupsrequestv1_resources required: true description: Create new User Group(s). Maximum 500 User Group(s) allowed per customer. name: cs-create-user-groups outputs: - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.user_group_id description: '' type: String - arguments: - description: '' isArray: true name: k8sreg_createawsaccreq_resources required: true description: Creates a new AWS account in our system for a customer and generates the installation script. name: cs-createaws-account - arguments: - description: '' isArray: true name: domain_cidgroupsrequestv1_resources required: true description: Create new CID Group(s). Maximum 500 CID Group(s) allowed. name: cs-createcid-groups outputs: - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.name description: '' type: String - arguments: - description: '' isArray: true name: registration_awsaccountcreaterequestextv2_resources required: true description: Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access. name: cs-createcspm-aws-account - arguments: - description: '' isArray: true name: registration_gcpaccountcreaterequestextv1_resources required: true description: Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access. name: cs-createcspmgcp-account - arguments: - description: '' name: requests_mlexclusioncreatereqv1_comment - description: '' isArray: true name: requests_mlexclusioncreatereqv1_excluded_from - description: '' isArray: true name: requests_mlexclusioncreatereqv1_groups - description: '' name: requests_mlexclusioncreatereqv1_value description: Create the ML exclusions. name: cs-createml-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: A collection of policies to create. isArray: true name: requests_creatertresponsepoliciesv1_resources required: true description: Create Response Policies by specifying details about the policy to create. name: cs-creatert-response-policies - arguments: - description: '' name: api_rulecreatev1_comment required: true - description: '' name: api_rulecreatev1_description required: true - description: '' name: api_rulecreatev1_disposition_id required: true - description: '' isArray: true name: api_rulecreatev1_field_values required: true - description: '' name: api_rulecreatev1_name required: true - description: '' name: api_rulecreatev1_pattern_severity required: true - description: '' name: api_rulecreatev1_rulegroup_id required: true - description: '' name: api_rulecreatev1_ruletype_id required: true description: Create a rule within a rule group. Returns the rule. name: cs-createrule - arguments: - description: The user id. name: X_CS_USERNAME required: true - description: A rule group ID from which to copy rules. If this is provided then the 'rules' property of the body is ignored. name: clone_id - description: If this flag is set to true then the rules will be cloned from the clone_id from the CrowdStrike Firewal Rule Groups Li ary. name: li_ary - description: Audit log comment for this action. name: comment - description: '' name: fwmgr_api_rulegroupcreaterequestv1_description required: true - description: '' name: fwmgr_api_rulegroupcreaterequestv1_enabled required: true - description: '' name: fwmgr_api_rulegroupcreaterequestv1_name required: true - description: '' isArray: true name: fwmgr_api_rulegroupcreaterequestv1_rules required: true description: Create new rule group on a platform for a customer with a name and description, and return the ID. name: cs-createrulegroup - arguments: - description: '' name: api_rulegroupcreaterequestv1_comment required: true - description: '' name: api_rulegroupcreaterequestv1_description required: true - description: '' name: api_rulegroupcreaterequestv1_name required: true - description: '' name: api_rulegroupcreaterequestv1_platform required: true description: Create a rule group for a platform with a name and an optional description. Returns the rule group. name: cs-createrulegroup-mixin0 - arguments: - description: '' name: requests_svexclusioncreatereqv1_comment - description: '' isArray: true name: requests_svexclusioncreatereqv1_groups - description: '' name: requests_svexclusioncreatereqv1_value description: Create the sensor visibility exclusions. name: cs-createsv-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset - description: The maximum records to return. [1-2500]. name: limit - auto: PREDEFINED description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort predefined: - score.asc - score.desc - timestamp.asc - timestamp.desc description: Query environment wide CrowdScore and return the entity data. name: cs-crowd-score outputs: - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.resources.score description: '' type: Number - contextPath: CrowdStrike.apiMsaEnvironmentScoreResponse.resources.timestamp description: '' type: String - description: Check current installation token settings. name: cs-customersettingsread outputs: - contextPath: CrowdStrike.apicustomerSettingsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apicustomerSettingsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apicustomerSettingsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apicustomerSettingsResponseV1.resources.max_active_tokens description: '' type: Number - contextPath: CrowdStrike.apicustomerSettingsResponseV1.resources.tokens_required description: '' type: Boolean - arguments: - description: ID of the action. name: id_ required: true description: Delete an action from a monitoring rule based on the action ID. name: cs-delete-actionv1 outputs: - contextPath: CrowdStrike.domainQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueryResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message_key description: '' type: String - arguments: - description: The IDs of the Device Control Policies to delete. isArray: true name: ids required: true description: Delete a set of Device Control Policies by specifying their IDs. name: cs-delete-device-control-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The IDs of the Firewall Policies to delete. isArray: true name: ids required: true description: Delete a set of Firewall Policies by specifying their IDs. name: cs-delete-firewall-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The IDs of the Host Groups to delete. isArray: true name: ids required: true description: Delete a set of Host Groups by specifying their IDs. name: cs-delete-host-groups outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Notifications IDs. isArray: true name: ids required: true description: Delete notifications based on IDs. Notifications cannot be recovered after they are deleted. name: cs-delete-notificationsv1 outputs: - contextPath: CrowdStrike.domainNotificationIDResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationIDResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationIDResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationIDResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationIDResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationIDResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationIDResponse.errors.message_key description: '' type: String - arguments: - description: The IDs of the Prevention Policies to delete. isArray: true name: ids required: true description: Delete a set of Prevention Policies by specifying their IDs. name: cs-delete-prevention-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: ID of a report. name: ids required: true description: Delete report based on the report ID. Operation can be checked for success by polling for the report ID on the report-summaries endpoint. name: cs-delete-report - arguments: - description: User UUID. name: X_CS_USERUUID - description: IDs of rules. isArray: true name: ids required: true description: Delete monitoring rules. name: cs-delete-rulesv1 outputs: - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message_key description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: The file SHA256. name: ids required: true description: Removes a sample, including file, meta and submissions from the collection. name: cs-delete-samplev2 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: The file SHA256. name: ids required: true description: Removes a sample, including file, meta and submissions from the collection. name: cs-delete-samplev3 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The IDs of the Sensor Update Policies to delete. isArray: true name: ids required: true description: Delete a set of Sensor Update Policies by specifying their IDs. name: cs-delete-sensor-update-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of the exclusions to delete. isArray: true name: ids required: true - description: Explains why this exclusions was deleted. name: comment description: Delete the sensor visibility exclusions by id. name: cs-delete-sensor-visibility-exclusionsv1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. name: user_uuid required: true description: Delete a user permanently. name: cs-delete-user outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: '' isArray: true name: domain_usergroupmembersrequestv1_resources required: true description: Delete User Group members entry. name: cs-delete-user-group-members outputs: - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.resources.user_group_id description: '' type: String - arguments: - description: User Group IDs. isArray: true name: user_group_ids required: true description: Delete User Group(s) by ID(s). name: cs-delete-user-groups outputs: - contextPath: CrowdStrike.msaEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaEntitiesResponse.errors.message description: '' type: String - arguments: - description: IDs of accounts to remove. isArray: true name: ids required: true description: Delete a set of AWS Accounts by specifying their IDs. name: cs-deleteaws-accounts outputs: - contextPath: CrowdStrike.modelsBaseResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsBaseResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsBaseResponseV1.errors.message description: '' type: String - arguments: - description: AWS Account IDs. isArray: true name: ids required: true description: Delete AWS accounts. name: cs-deleteaws-accounts-mixin0 outputs: - contextPath: CrowdStrike.msaMetaInfo.powered_by description: '' type: String - contextPath: CrowdStrike.msaMetaInfo.query_time description: '' type: Unknown - contextPath: CrowdStrike.msaMetaInfo.trace_id description: '' type: String - contextPath: CrowdStrike.msaMetaInfo.powered_by description: '' type: String - contextPath: CrowdStrike.msaMetaInfo.query_time description: '' type: Unknown - contextPath: CrowdStrike.msaMetaInfo.trace_id description: '' type: String - arguments: - description: '' isArray: true name: domain_cidgroupmembersrequestv1_resources required: true description: Delete CID Group members entry. name: cs-deletecid-group-members outputs: - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.resources.cid_group_id description: '' type: String - arguments: - description: CID group ids to be deleted. isArray: true name: cid_group_ids required: true description: Delete CID Group(s) by ID(s). name: cs-deletecid-groups outputs: - contextPath: CrowdStrike.msaEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaEntitiesResponse.errors.message description: '' type: String - arguments: - description: AWS account IDs to remove. isArray: true name: ids - description: AWS organization IDs to remove. isArray: true name: organization_ids description: Deletes an existing AWS account or organization in our system. name: cs-deletecspm-aws-account outputs: - contextPath: CrowdStrike.registrationBaseResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationBaseResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationBaseResponseV1.errors.message description: '' type: String - arguments: - description: Azure subscription IDs to remove. isArray: true name: ids required: true description: Deletes an Azure subscription from the system. name: cs-deletecspm-azure-account outputs: - contextPath: CrowdStrike.registrationBaseResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationBaseResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationBaseResponseV1.errors.message description: '' type: String - arguments: - description: '' isArray: true name: domain_mssprolerequestv1_resources required: true description: Delete MSSP Role assignment(s) between User Group and CID Group. User Group ID and CID Group ID have to be specified in request. Only specified roles are removed if specified in request payload, else association between User Group and CID Group is dissolved completely (if no roles specified). name: cs-deleted-roles outputs: - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.user_group_id description: '' type: String - arguments: - description: The ids of the exclusions to delete. isArray: true name: ids required: true - description: Explains why this exclusions was deleted. name: comment description: Delete the IOA exclusions by id. name: cs-deleteioa-exclusionsv1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of the exclusions to delete. isArray: true name: ids required: true - description: Explains why this exclusions was deleted. name: comment description: Delete the ML exclusions by id. name: cs-deleteml-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: The IDs of the Response Policies to delete. isArray: true name: ids required: true description: Delete a set of Response Policies by specifying their IDs. name: cs-deletert-response-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The user id. name: X_CS_USERNAME required: true - description: The IDs of the rule groups to be deleted. isArray: true name: ids required: true - description: Audit log comment for this action. name: comment description: Delete rule group entities by ID. name: cs-deleterulegroups outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - description: Explains why the entity is being deleted. name: comment - description: The IDs of the entities. isArray: true name: ids required: true description: Delete rule groups by ID. name: cs-deleterulegroups-mixin0 outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: The parent rule group. name: rule_group_id required: true - description: Explains why the entity is being deleted. name: comment - description: The IDs of the entities. isArray: true name: ids required: true description: Delete rules from a rule group by ID. name: cs-deleterules outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: type_ required: true - description: The string representation of the indicator. name: value required: true description: Number of hosts in your customer account that have observed a given custom IOC. name: cs-devices-count outputs: - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.resources.device_count description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.resources.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.resources.limit_exceeded description: '' type: Boolean - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.resources.type description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCDevicesCount.resources.value description: '' type: String - arguments: - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: type_ required: true - description: The string representation of the indicator. name: value required: true - description: The first process to return, where 0 is the latest offset. Use with the offset meter to manage pagination of results. name: limit - description: The first process to return, where 0 is the latest offset. Use with the limit meter to manage pagination of results. name: offset description: Find hosts that have observed a given custom IOC. For details about those hosts, use GET /devices/entities/devices/v2. name: cs-devices-ran-on outputs: - contextPath: CrowdStrike.apiMsaReplyDevicesRanOn.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyDevicesRanOn.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyDevicesRanOn.errors.message description: '' type: String - arguments: - description: SHA256 of the installer to download. name: id_ required: true description: Download sensor installer by SHA256 ID. name: cs-download-sensor-installer-by-id - arguments: - description: ProcessID for the running process you want to lookup. isArray: true name: ids required: true description: For the provided ProcessID retrieve the process details. name: cs-entitiesprocesses outputs: - contextPath: CrowdStrike.apiMsaProcessDetailResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaProcessDetailResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.command_line description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.device_id description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.file_name description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.process_id description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.process_id_local description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.start_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.start_timestamp_raw description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.stop_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaProcessDetailResponse.resources.stop_timestamp_raw description: '' type: String - arguments: - description: Action IDs. isArray: true name: ids required: true description: Get actions based on their IDs. IDs can be retrieved using the GET /queries/actions/v1 endpoint. name: cs-get-actionsv1 outputs: - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.cid description: The ID of the customer who created the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.created_timestamp description: The date when the action was created. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.frequency description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.id description: The ID of the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.rule_id description: The ID of the rule on which this action is attached. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.status description: The action status. It can be either 'enabled' or 'muted'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.type description: The action type. The only type currently supported is 'email'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.updated_timestamp description: The date when the action was updated. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.user_uuid description: The UUID of the user who created the action. type: String - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get detect aggregates as specified via json in request body. name: cs-get-aggregate-detects outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: ID of an artifact, such as an IOC pack, PCAP file, or actor image. Find an artifact ID in a report or summary. name: id_ required: true - description: The name given to your downloaded file. name: name - description: Format used to compress your downloaded file. Currently, you must provide the value `gzip`, the only valid format. name: Accept_Encoding description: Download IOC packs, PCAP files, and other analysis artifacts. name: cs-get-artifacts - arguments: - description: One or more agent IDs, which you can find in the data.zta file, or the Falcon console. isArray: true name: ids required: true description: Get Zero Trust Assessment data for one or more hosts by providing agent IDs (AID) and a customer ID (CID). name: cs-get-assessmentv1 outputs: - contextPath: CrowdStrike.domainAssessmentsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainAssessmentsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.aid description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.event_platform description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.modified_time description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.sensor_file_status description: '' type: String - contextPath: CrowdStrike.domainAssessmentsResponse.resources.system_serial_number description: '' type: String - description: Show role IDs for all roles available in your customer account. For more information on each role, provide the role ID to `/customer/entities/roles/v1`. name: cs-get-available-role-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: Get details on behaviors by providing behavior IDs. name: cs-get-behaviors outputs: - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.aid description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.behavior_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.cmdline description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.compound_tto description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.detection_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.domain description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.filepath description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.incident_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.ioc_source description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.ioc_type description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.ioc_value description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.objective description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.pattern_disposition description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.pattern_id description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.tactic description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.technique description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.template_instance_id description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaExternalBehaviorResponse.resources.user_name description: '' type: String - arguments: - description: CID of a child customer. isArray: true name: ids required: true description: Get link to child customer by child CID(s). name: cs-get-children outputs: - contextPath: CrowdStrike.domainChildrenResponseV1.resources.checksum description: '' type: String - contextPath: CrowdStrike.domainChildrenResponseV1.resources.child_cid description: '' type: String - contextPath: CrowdStrike.domainChildrenResponseV1.resources.child_gcid description: '' type: String - contextPath: CrowdStrike.domainChildrenResponseV1.resources.child_of description: '' type: String - contextPath: CrowdStrike.domainChildrenResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainChildrenResponseV1.resources.status description: '' type: String - arguments: - description: SubscriptionIDs of accounts to select for this status operation. If this is empty then all accounts are returned. isArray: true name: ids - description: Type of scan, dry or full, to perform on selected accounts. name: scan_type description: Return information about Azure account registration. name: cs-get-cloudconnectazure-entities-account-v1 outputs: - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.status description: Account registration status. type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.subscription_id description: Azure Subscription ID. type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.tenant_id description: Azure Tenant ID to use. type: String - description: Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment. name: cs-get-cloudconnectazure-entities-userscriptsdownload-v1 outputs: - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - arguments: - description: SubscriptionIDs of accounts to select for this status operation. If this is empty then all accounts are returned. isArray: true name: ids - description: Type of scan, dry or full, to perform on selected accounts. name: scan_type - description: Account status to filter results by. name: status - description: The maximum records to return. Defaults to 100. name: limit - description: The offset to start retrieving records from. name: offset description: Return information about Azure account registration. name: cs-get-cloudconnectcspmazure-entities-account-v1 outputs: - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.status description: Account registration status. type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.subscription_id description: Azure Subscription ID. type: String - contextPath: CrowdStrike.registrationAzureAccountResponseV1.resources.tenant_id description: Azure Tenant ID to use. type: String - arguments: - description: Tenant ID to generate script for. Defaults to most recently registered tenant. name: tenant_id description: Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment. name: cs-get-cloudconnectcspmazure-entities-userscriptsdownload-v1 outputs: - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - arguments: - description: Cluster name. For EKS it will be cluster ARN. isArray: true name: cluster_names - description: Cluster Account id. For EKS it will be AWS account ID. isArray: true name: account_ids - description: Cloud location. isArray: true name: locations - auto: PREDEFINED description: Cluster Service. name: cluster_service predefined: - eks - description: Limit returned accounts. name: limit - description: Offset returned accounts. name: offset description: Provides the clusters acknowledged by the Kubernetes Protection service. name: cs-get-clusters outputs: - contextPath: CrowdStrike.k8sregGetClustersResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregGetClustersResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.account_id description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.cid description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.cluster_id description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.cluster_name description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.cluster_service description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.created_at description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.last_heartbeat_at description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.location description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.status description: '' type: String - contextPath: CrowdStrike.k8sregGetClustersResp.resources.updated_at description: '' type: String - arguments: - description: The first item to return, where 0 is the latest item. Use with the limit meter to manage pagination of results. name: offset - description: 'The number of items to return in this response (default: 100, max: 500). Use with the offset meter to manage pagination of results.' name: limit - description: 'Sort items using their properties. Common sort options include: ul li version|asc /li li release_date|desc /li /ul.' name: sort - description: 'Filter items using a query in Falcon Query Language (FQL). An asterisk wildcard includes all results. Common filter options include: ul li platform:"windows" /li li version: "5.2" /li /ul.' name: filter_ description: Get sensor installer details by provided query. name: cs-get-combined-sensor-installers-by-query outputs: - contextPath: CrowdStrike.domainSensorInstallersV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.description description: installer description. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_size description: file size. type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_type description: file type. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.name description: installer file name. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.platform description: supported platform. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.release_date description: release date. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.sha256 description: sha256. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.version description: version of the installer. type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: View information about detections. name: cs-get-detect-summaries outputs: - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.assigned_to_name description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.assigned_to_uid description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.alleged_filetype description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.behavior_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.cmdline description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.confidence description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.container_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.control_graph_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.description description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.device_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.display_name description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.filename description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.filepath description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.ioc_description description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.ioc_source description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.ioc_type description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.ioc_value description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.md5 description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.objective description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.pattern_disposition description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.rule_instance_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.rule_instance_version description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.scenario description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.severity description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.sha256 description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.tactic description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.tactic_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.technique description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.technique_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.template_instance_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.timestamp description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.triggering_process_graph_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.user_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.behaviors.user_name description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.detection_id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.email_sent description: '' type: Boolean - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.first_behavior description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.last_behavior description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.max_confidence description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.max_severity description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.max_severity_displayname description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.overwatch_notes description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.quarantined_files.id description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.quarantined_files.paths description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.quarantined_files.sha256 description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.quarantined_files.state description: '' type: String - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.seconds_to_resolved description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.seconds_to_triaged description: '' type: Number - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.show_in_ui description: '' type: Boolean - contextPath: CrowdStrike.domainMsaDetectSummariesResponse.resources.status description: '' type: String - arguments: - description: The IDs of the Device Control Policies to return. isArray: true name: ids required: true description: Retrieve a set of Device Control Policies by specifying their IDs. name: cs-get-device-control-policies outputs: - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve device count collection Ids that match the provided FQL filter, criteria with scrolling enabled. name: cs-get-device-count-collection-queries-by-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The host agentIDs used to get details on. isArray: true name: ids required: true description: Get details on one or more hosts by providing agent IDs (AID). You can get a host's agent IDs (AIDs) from the /devices/queries/devices/v1 endpoint, the Falcon console or the Streaming API. name: cs-get-device-details outputs: - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.errors.code description: '' type: Number - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.errors.id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.errors.message description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.agent_version description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.bios_version description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.build_number description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.cid description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.device_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.email description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.external_ip description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.first_seen description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.group_hash description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.hostname description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.instance_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.last_seen description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.local_ip description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.mac_address description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.major_version description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.minor_version description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.os_version description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.platform_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.platform_name description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_name description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.product_type description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.provision_status description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.release_group description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.serial_number description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.service_provider description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.site_name description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.status description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.domainDeviceDetailsResponseSwagger.resources.zone_group description: '' type: String - arguments: - description: The IDs of the Firewall Policies to return. isArray: true name: ids required: true description: Retrieve a set of Firewall Policies by specifying their IDs. name: cs-get-firewall-policies outputs: - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - arguments: - description: Cluster name. For EKS it will be cluster ARN. name: cluster_name required: true description: Provides a sample Helm values.yaml file for a customer to install alongside the agent Helm chart. name: cs-get-helm-values-yaml - arguments: - description: The IDs of the Host Groups to return. isArray: true name: ids required: true description: Retrieve a set of Host Groups by specifying their IDs. name: cs-get-host-groups outputs: - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: Get details on incidents by providing incident IDs. name: cs-get-incidents outputs: - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.assigned_to description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.assigned_to_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.created description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.end description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.count description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.has_detect description: '' type: Boolean - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.has_overwatch description: '' type: Boolean - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.has_prevented description: '' type: Boolean - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.timestamp_max description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.events_histogram.timestamp_min description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.fine_score description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.agent_load_flags description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.agent_local_time description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.agent_version description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.bios_version description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.cid description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.config_id_base description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.config_id_build description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.config_id_platform description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.device_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.external_ip description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.first_login_user description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.first_seen description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.hostname description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.instance_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.last_login_user description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.last_seen description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.local_ip description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.mac_address description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.machine_domain description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.major_version description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.minor_version description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.os_version description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.platform_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.platform_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.pod_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.pod_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.pod_namespace description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.product_type description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.product_type_desc description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.release_group description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.service_provider description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.site_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.status description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.system_manufacturer description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.hosts.system_product_name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.incident_id description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.incident_type description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.lm_hosts_capped description: '' type: Boolean - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.start description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.state description: '' type: String - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.status description: '' type: Number - contextPath: CrowdStrike.apiMsaExternalIncidentResponse.resources.visibility description: '' type: Number - arguments: - description: The IDs of the actors you want to retrieve. isArray: true name: ids required: true - description: 'The fields to return, or a predefined set of fields in the form of the collection name surrounded by two underscores like: \_\_\ collection\ \_\_. Ex: slug \_\_full\_\_. Defaults to \_\_basic\_\_.' isArray: true name: fields description: Retrieve specific actors using their actor IDs. name: cs-get-intel-actor-entities outputs: - contextPath: CrowdStrike.domainActorsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.actor_type description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.first_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.known_as description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.last_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.origins.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.origins.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.url description: '' type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: Retrieve specific indicators using their indicator IDs. name: cs-get-intel-indicator-entities outputs: - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.code description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.message description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources._marker description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.created_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.last_valid_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.name description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.last_updated description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.malicious_confidence description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.published_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.created_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.last_valid_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.type description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.type description: '' type: String - arguments: - description: The IDs of the reports you want to retrieve. isArray: true name: ids required: true - description: 'The fields to return, or a predefined set of fields in the form of the collection name surrounded by two underscores like: \_\_\ collection\ \_\_. Ex: slug \_\_full\_\_. Defaults to \_\_basic\_\_.' isArray: true name: fields description: Retrieve specific reports using their report IDs. name: cs-get-intel-report-entities outputs: - contextPath: CrowdStrike.domainNewsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.actors.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.actors.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.tags.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.url description: '' type: String - arguments: - description: The ID of the report you want to download as a PDF. name: id_ required: true description: Return a Report PDF attachment. name: cs-get-intel-reportpdf - arguments: - description: The ids of rules to return. isArray: true name: ids required: true description: Retrieve details for rule sets for the specified ids. name: cs-get-intel-rule-entities outputs: - contextPath: CrowdStrike.domainRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainRulesResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainRulesResponse.resources.type description: '' type: String - arguments: - description: Choose the format you want the rule set in. name: Accept - description: The ID of the rule set. name: id_ required: true - description: Choose the format you want the rule set in. Valid formats are zip and gzip. Defaults to zip. name: format description: Download earlier rule sets. name: cs-get-intel-rule-file - arguments: - description: Choose the format you want the rule set in. name: Accept - description: 'The rule news report type. Accepted values: snort-suricata-master snort-suricata-update snort-suricata-changelog yara-master yara-update yara-changelog common-event-format netwitness.' name: type_ required: true - description: Choose the format you want the rule set in. Valid formats are zip and gzip. Defaults to zip. name: format description: Download the latest rule set. name: cs-get-latest-intel-rule-file - arguments: - auto: PREDEFINED description: Cloud Provider. isArray: true name: clouds predefined: - aws - azure - gcp description: Provides the cloud locations acknowledged by the Kubernetes Protection service. name: cs-get-locations outputs: - contextPath: CrowdStrike.k8sregGetLocationsResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregGetLocationsResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregGetLocationsResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregGetLocationsResp.resources.cloud description: '' type: String - contextPath: CrowdStrike.k8sregGetLocationsResp.resources.location description: '' type: String - arguments: - description: The file SHA256. isArray: true name: ids required: true description: Download a file indexed by MalQuery. Specify the file using its SHA256. Only one file is supported at this time. name: cs-get-mal-query-downloadv1 - arguments: - description: Multidownload job id. name: ids required: true description: Fetch a zip archive with password 'infected' containing the samples. Call this once the /entities/samples-multidownload request has finished processing. name: cs-get-mal-query-entities-samples-fetchv1 - arguments: - description: The file SHA256. isArray: true name: ids required: true description: Retrieve indexed files metadata by their hash. name: cs-get-mal-query-metadatav1 outputs: - contextPath: CrowdStrike.malquerySampleMetadataResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malquerySampleMetadataResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malquerySampleMetadataResponse.resources.sha256 description: Sample SHA256. type: String - description: Get information about search and download quotas in your environment. name: cs-get-mal-query-quotasv1 outputs: - contextPath: CrowdStrike.malqueryRateLimitsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryRateLimitsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryRateLimitsResponse.errors.message description: '' type: String - arguments: - description: Identifier of a MalQuery request. isArray: true name: ids required: true description: Check the status and results of an asynchronous request, such as hunt or exact-search. Supports a single request id at this time. name: cs-get-mal-query-requestv1 outputs: - contextPath: CrowdStrike.malqueryRequestResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryRequestResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryRequestResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryRequestResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryRequestResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryRequestResponse.resources.yara_rule description: Search YARA rule. type: String - arguments: - description: Notification IDs. isArray: true name: ids required: true description: Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match.This endpoint will return translated notification content. The only target language available is English. A single notification can be translated per request. name: cs-get-notifications-detailed-translatedv1 outputs: - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message_key description: '' type: String - arguments: - description: Notification IDs. isArray: true name: ids required: true description: Get detailed notifications based on their IDs. These include the raw intelligence content that generated the match. name: cs-get-notifications-detailedv1 outputs: - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationDetailsResponseV1.errors.message_key description: '' type: String - arguments: - description: Notification IDs. isArray: true name: ids required: true description: Get notifications based on their IDs. IDs can be retrieved using the GET /queries/notifications/v1 endpoint. This endpoint will return translated notification content. The only target language available is English. name: cs-get-notifications-translatedv1 outputs: - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - arguments: - description: Notification IDs. isArray: true name: ids required: true description: Get notifications based on their IDs. IDs can be retrieved using the GET /queries/notifications/v1 endpoint. name: cs-get-notificationsv1 outputs: - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - arguments: - description: The IDs of the Prevention Policies to return. isArray: true name: ids required: true description: Retrieve a set of Prevention Policies by specifying their IDs. name: cs-get-prevention-policies outputs: - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: ID of a report. Find a report ID from the response when submitting a malware sample or search with `/falconx/queries/reports/v1`. isArray: true name: ids required: true description: Get a full sandbox report. name: cs-get-reports outputs: - contextPath: CrowdStrike.falconxReportV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.first_activity_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.image_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.known_as description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.last_activity_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.short_description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.thumbnail_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.updated_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.errors.message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.input description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.family description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.file_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.first_seen_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.label description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.md5 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.sha1 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.verdict description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.architecture description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.address description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.associated_runtime.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.associated_runtime.pid description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.compromised description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.country description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.protocol description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.address description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.compromised description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.country description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.domain description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_creation_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_name_servers description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_organization description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.environment_description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_available_to_download description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.md5 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.runtime_process description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.sha1 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.threat_level description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.threat_level_readable description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.filename description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.process description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.source description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_imports.module description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.header description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host_ip description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host_port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.method description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.response_code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.response_phrase description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.incidents.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.ioc_report_broad_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.ioc_report_strict_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_forensics.stream_uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_forensics.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_strings_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.attack_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.tactic description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.technique description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.packer description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.pcap_report_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.command_line description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.mask description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.icon_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.normalized_path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.parent_uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.pid description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.process_flags.data description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.process_flags.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.key description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.operation description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.status description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.status_human_readable description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.cls_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.dispatch_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.argument_number description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.comment description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.meaning description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.result description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.status description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.executed description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.file_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.human_keywords description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.instructions_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.matched_signatures.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.matched_signatures.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.attack_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.category description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.identifier description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.relevance description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.threat_level description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.threat_level_human description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.type description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submission_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submit_url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.category description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.destination_ip description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.destination_port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.protocol description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.sid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.target_url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.threat_score description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.verdict description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.version_info.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.version_info.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_bitness description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_edition description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_service_pack description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_version description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.verdict description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.first_activity_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.image_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.known_as description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.last_activity_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.origins.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.short_description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_countries.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.slug description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.target_industries.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.actors.thumbnail_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.updated_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.intel.related_indicators.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_broad_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.ioc_report_strict_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.errors.message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.input description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.family description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.file_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.first_seen_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.label description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.md5 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.sha1 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.resources.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.malquery.verdict description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.architecture description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.address description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.associated_runtime.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.associated_runtime.pid description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.compromised description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.country description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.contacted_hosts.protocol description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.address description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.compromised description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.country description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.domain description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_creation_timestamp description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_name_servers description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.dns_requests.registrar_organization description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.environment_description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_message description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.error_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_available_to_download description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.md5 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.runtime_process description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.sha1 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.threat_level description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_files.threat_level_readable description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.filename description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.process description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.source description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.extracted_interesting_strings.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_imports.module description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_size description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.file_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.header description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host_ip description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.host_port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.method description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.response_code description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.response_phrase description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.http_requests.url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.incidents.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.ioc_report_broad_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.ioc_report_strict_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_forensics.stream_uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_forensics.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.memory_strings_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.attack_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.tactic description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.mitre_attacks.technique description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.packer description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.pcap_report_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.command_line description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.mask description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.file_accesses.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.id description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.handles.type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.icon_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.normalized_path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.parent_uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.pid description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.process_flags.data description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.process_flags.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.key description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.operation description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.path description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.status description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.status_human_readable description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.registry.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.cls_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.dispatch_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.argument_number description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.comment description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.meaning description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.parameters.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.result description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.script_calls.status description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.executed description: '' type: Boolean - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.file_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.human_keywords description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.instructions_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.matched_signatures.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.matched_signatures.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.streams.uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.processes.uid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.attack_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.category description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.identifier description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.origin description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.relevance description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.threat_level description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.threat_level_human description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.signatures.type description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submission_type description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.submit_url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.category description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.description description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.destination_ip description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.destination_port description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.protocol description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.suricata_alerts.sid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.target_url description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.threat_score description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.verdict description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.version_info.id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.version_info.value description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_bitness description: '' type: Number - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_edition description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_service_pack description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.sandbox.windows_version_version description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.falconxReportV1Response.resources.verdict description: '' type: String - arguments: - description: ID of a role. Find a role ID from `/customer/queries/roles/v1` or `/users/queries/roles/v1`. isArray: true name: ids required: true description: Get info about a role. name: cs-get-roles outputs: - contextPath: CrowdStrike.domainUserRoleResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.display_name description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.display_name description: '' type: String - contextPath: CrowdStrike.domainUserRoleResponse.resources.id description: '' type: String - arguments: - description: 'MSSP Role assignment is of the format user_group_id : cid_group_id.' isArray: true name: ids required: true description: Get MSSP Role assignment(s). MSSP Role assignment is of the format :. name: cs-get-roles-byid outputs: - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.user_group_id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.domainMSSPRoleResponseV1.resources.user_group_id description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: IDs of rules. isArray: true name: ids required: true description: Get monitoring rules rules by provided IDs. name: cs-get-rulesv1 outputs: - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.created_timestamp description: The creation time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.filter description: The FQL filter contained in a rule and used for searching. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.id description: The ID of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.name description: The name for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.permissions description: The permissions of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.priority description: The priority of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status description: The status of a rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status_message description: The detailed status message. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.topic description: The topic of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.updated_timestamp description: The last updated time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_id description: The user ID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_name description: The user name of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_uuid description: The UUID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.created_timestamp description: The creation time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.filter description: The FQL filter contained in a rule and used for searching. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.id description: The ID of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.name description: The name for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.permissions description: The permissions of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.priority description: The priority of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status description: The status of a rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status_message description: The detailed status message. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.topic description: The topic of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.updated_timestamp description: The last updated time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_id description: The user ID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_name description: The user name of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_uuid description: The UUID of the user that created a given rule. type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: The file SHA256. name: ids required: true - description: Flag whether the sample should be zipped and password protected with pass='infected'. name: password_protected description: Retrieves the file associated with the given ID (SHA256). name: cs-get-samplev2 - arguments: - description: User UUID. name: X_CS_USERUUID - description: The file SHA256. name: ids required: true - description: Flag whether the sample should be zipped and password protected with pass='infected'. name: password_protected description: Retrieves the file associated with the given ID (SHA256). name: cs-get-samplev3 - arguments: - description: ID of a submitted scan. isArray: true name: ids required: true description: Check the status of a volume scan. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute. name: cs-get-scans outputs: - contextPath: CrowdStrike.mlscannerScanV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerScanV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.error description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.sha256 description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.verdict description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.status description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerScanV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.error description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.sha256 description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.samples.verdict description: '' type: String - contextPath: CrowdStrike.mlscannerScanV1Response.resources.status description: '' type: String - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get scans aggregations as specified via json in request body. name: cs-get-scans-aggregates - arguments: - description: The first item to return, where 0 is the latest item. Use with the limit meter to manage pagination of results. name: offset - description: 'The number of items to return in this response (default: 100, max: 500). Use with the offset meter to manage pagination of results.' name: limit - description: 'Sort items using their properties. Common sort options include: ul li version|asc /li li release_date|desc /li /ul.' name: sort - description: 'Filter items using a query in Falcon Query Language (FQL). An asterisk wildcard includes all results. Common filter options include: ul li platform:"windows" /li li version: "5.2" /li /ul.' name: filter_ description: Get sensor installer IDs by provided query. name: cs-get-sensor-installers-by-query outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The IDs of the installers. isArray: true name: ids required: true description: Get sensor installer details by provided SHA256 IDs. name: cs-get-sensor-installers-entities outputs: - contextPath: CrowdStrike.domainSensorInstallersV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.description description: installer description. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_size description: file size. type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_type description: file type. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.name description: installer file name. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.platform description: supported platform. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.release_date description: release date. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.sha256 description: sha256. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.version description: version of the installer. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.description description: installer description. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_size description: file size. type: Number - contextPath: CrowdStrike.domainSensorInstallersV1.resources.file_type description: file type. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.name description: installer file name. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.platform description: supported platform. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.release_date description: release date. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.sha256 description: sha256. type: String - contextPath: CrowdStrike.domainSensorInstallersV1.resources.version description: version of the installer. type: String - description: Get CCID to use with sensor installers. name: cs-get-sensor-installersccid-by-query outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The IDs of the Sensor Update Policies to return. isArray: true name: ids required: true description: Retrieve a set of Sensor Update Policies by specifying their IDs. name: cs-get-sensor-update-policies outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: The IDs of the Sensor Update Policies to return. isArray: true name: ids required: true description: Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs. name: cs-get-sensor-update-policiesv2 outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - arguments: - description: The ids of the exclusions to retrieve. isArray: true name: ids required: true description: Get a set of Sensor Visibility Exclusions by specifying their IDs. name: cs-get-sensor-visibility-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value_hash description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: ID of a submitted malware sample. Find a submission ID from the response when submitting a malware sample or search with `/falconx/queries/submissions/v1`. isArray: true name: ids required: true description: Check the status of a sandbox analysis. Time required for analysis varies but is usually less than 15 minutes. name: cs-get-submissions outputs: - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.action_script description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.command_line description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.document_password description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.enable_tor description: '' type: Boolean - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_date description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_time description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.url description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.state description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.action_script description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.command_line description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.document_password description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.enable_tor description: '' type: Boolean - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_date description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_time description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.url description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.state description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_uuid description: '' type: String - arguments: - description: ID of a summary. Find a summary ID from the response when submitting a malware sample or search with `/falconx/queries/reports/v1`. isArray: true name: ids required: true description: Get a short summary version of a sandbox report. name: cs-get-summary-reports outputs: - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.id description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.slug description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.environment_description description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_message description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_origin description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.file_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.incidents.name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submission_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submit_url description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.threat_score description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.verdict description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.verdict description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.id description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.intel.actors.slug description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_broad_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_csv_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_json_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_maec_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.ioc_report_strict_stix_artifact_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.environment_description description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_message description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_origin description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.error_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.file_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.incidents.name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submission_type description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.submit_url description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.threat_score description: '' type: Number - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.sandbox.verdict description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSummaryReportV1Response.resources.verdict description: '' type: String - arguments: - description: User Group IDs to search for. name: user_group_ids required: true description: Get User Group members by User Group ID(s). name: cs-get-user-group-members-byid outputs: - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.resources.user_group_id description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupMembersResponseV1.resources.user_group_id description: '' type: String - arguments: - description: User Group IDs to search for. isArray: true name: user_group_ids required: true description: Get User Group by ID(s). name: cs-get-user-groups-byid outputs: - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.user_group_id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.user_group_id description: '' type: String - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. name: user_uuid required: true description: Show role IDs of roles assigned to a user. For more information on each role, provide the role ID to `/customer/entities/roles/v1`. name: cs-get-user-role-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: 'One or more vulnerability IDs (max: 400). Find vulnerability IDs with GET /spotlight/queries/vulnerabilities/v1.' isArray: true name: ids required: true description: Get details on vulnerabilities by providing one or more IDs. name: cs-get-vulnerabilities outputs: - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.aid description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.cid description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.closed_timestamp description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.status description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.updated_timestamp description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.aid description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.cid description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.closed_timestamp description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.status description: '' type: String - contextPath: CrowdStrike.domainSPAPIVulnerabilitiesEntitiesResponseV2.resources.updated_timestamp description: '' type: String - arguments: - description: IDs of accounts to retrieve details. isArray: true name: ids required: true description: Retrieve a set of AWS Accounts by specifying their IDs. name: cs-getaws-accounts outputs: - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - arguments: - description: AWS Account IDs. isArray: true name: ids - description: Filter by account status. name: status - description: Limit returned accounts. name: limit - description: Offset returned accounts. name: offset description: Provides a list of AWS accounts. name: cs-getaws-accounts-mixin0 outputs: - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.account_id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.aws_permissions_status.name description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.aws_permissions_status.status description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.cid description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.cloudformation_url description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.created_at description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.from_cspm description: '' type: Boolean - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.iam_role_arn description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.is_master description: '' type: Boolean - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.organization_id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.region description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.status description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.updated_at description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.account_id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.aws_permissions_status.name description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.aws_permissions_status.status description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.cid description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.cloudformation_url description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.created_at description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.from_cspm description: '' type: Boolean - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.iam_role_arn description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.is_master description: '' type: Boolean - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.organization_id description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.region description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.status description: '' type: String - contextPath: CrowdStrike.k8sregGetAWSAccountsResp.resources.updated_at description: '' type: String - description: Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts. name: cs-getaws-settings outputs: - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the centralized S3 bucket containing cloudtrail logs for all accounts. type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.created_timestamp description: Timestamp of when the settings were first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.last_modified_timestamp description: Timestamp of when the settings were last modified. type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.static_external_id description: By setting this value, all subsequent accounts that are provisioned will default to using this value as the external ID. type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the centralized S3 bucket containing cloudtrail logs for all accounts. type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.created_timestamp description: Timestamp of when the settings were first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.last_modified_timestamp description: Timestamp of when the settings were last modified. type: String - contextPath: CrowdStrike.modelsCustomerConfigurationsV1.resources.static_external_id description: By setting this value, all subsequent accounts that are provisioned will default to using this value as the external ID. type: String - arguments: - description: CID Group IDs to be searched on. isArray: true name: cid_group_ids required: true description: Get CID Group(s) by ID(s). name: cs-getcid-group-by-id outputs: - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.name description: '' type: String - arguments: - description: CID Group IDs to be searched on. isArray: true name: cid_group_ids required: true description: Get CID Group members by CID Group IDs. name: cs-getcid-group-members-by outputs: - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupMembersResponseV1.resources.cid_group_id description: '' type: String - arguments: - description: Type of scan, dry or full, to perform on selected accounts. name: scan_type - description: AWS account IDs. isArray: true name: ids - description: AWS organization IDs. isArray: true name: organization_ids - description: Account status to filter results by. name: status - description: The maximum records to return. Defaults to 100. name: limit - description: The offset to start retrieving records from. name: offset - auto: PREDEFINED description: Field to group by. name: group_by predefined: - organization description: Returns information about the current status of an AWS account. name: cs-getcspm-aws-account outputs: - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.account_id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_cloudtrail_bucket_name description: AWS CloudTrail bucket name to store logs. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_cloudtrail_region description: AWS CloudTrail region. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_permissions_status.name description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_permissions_status.status description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.cloudformation_url description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.eventbus_name description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.intermediate_role_arn description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.is_master description: '' type: Boolean - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.organization_id description: Up to 34 character AWS provided unique identifier for the organization. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.status description: Account registration status. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.account_id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_cloudtrail_bucket_name description: AWS CloudTrail bucket name to store logs. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_cloudtrail_region description: AWS CloudTrail region. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_permissions_status.name description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.aws_permissions_status.status description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.cloudformation_url description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.eventbus_name description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.intermediate_role_arn description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.is_master description: '' type: Boolean - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.organization_id description: Up to 34 character AWS provided unique identifier for the organization. type: String - contextPath: CrowdStrike.registrationAWSAccountResponseV2.resources.status description: Account registration status. type: String - description: Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment. name: cs-getcspm-aws-account-scripts-attachment outputs: - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.resources.bash description: '' type: String - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAWSProvisionGetAccountScriptResponseV2.resources.bash description: '' type: String - description: Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment. name: cs-getcspm-aws-console-setupur-ls outputs: - contextPath: CrowdStrike.registrationAWSAccountConsoleURL.account_id description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountConsoleURL.url description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountConsoleURL.account_id description: '' type: String - contextPath: CrowdStrike.registrationAWSAccountConsoleURL.url description: '' type: String - description: Return a script for customer to run in their cloud environment to grant us access to their Azure environment. name: cs-getcspm-azure-user-scripts outputs: - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationAzureProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - arguments: - description: Policy ID. name: ids required: true description: Given a policy ID, returns detailed policy information. name: cs-getcspm-policy outputs: - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.alert_logic description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.api_command description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cli_command description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_document description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_platform description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_platform_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_friendly description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.event_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.mitre_attack_cloud_matrix description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.mitre_attack_cloud_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_fail_query description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_pass_query description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_remediation description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_severity description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_statement description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.CreatedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.DeletedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.ID description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.UpdatedAt description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.alert_logic description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.api_command description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cli_command description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_document description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_platform description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_platform_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_friendly description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.cloud_service_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.event_type description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.mitre_attack_cloud_matrix description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.mitre_attack_cloud_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_fail_query description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_pass_query description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_remediation description: '' type: String - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_severity description: '' type: Number - contextPath: CrowdStrike.registrationPolicyResponseV1.resources.policy_statement description: '' type: String - arguments: - description: Service type to filter policy settings by. name: service - description: Policy ID. name: policy_id - auto: PREDEFINED description: 'Cloud Platform (e.g.: aws|azure|gcp).' name: cloud_platform predefined: - aws - azure - gcp description: Returns information about current policy settings. name: cs-getcspm-policy-settings outputs: - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.account_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.enabled description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tag_excluded description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tenant_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_timestamp description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_type description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.account_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.enabled description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tag_excluded description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tenant_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_timestamp description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_type description: '' type: String - arguments: - description: Cloud Platform. isArray: true name: cloud_platform description: Returns scan schedule configuration for one or more cloud platforms. name: cs-getcspm-scan-schedule outputs: - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.cloud_platform description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.next_scan_timestamp description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.scan_schedule description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.cloud_platform description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.next_scan_timestamp description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.scan_schedule description: '' type: String - arguments: - description: Type of scan, dry or full, to perform on selected accounts. name: scan_type - description: Parent IDs of accounts. isArray: true name: ids description: Returns information about the current status of an GCP account. name: cs-getcspmcgp-account outputs: - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.parent_id description: GCP ParentID. type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.status description: Account registration status. type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.parent_id description: GCP ParentID. type: String - contextPath: CrowdStrike.registrationGCPAccountResponseV1.resources.status description: Account registration status. type: String - description: Return a script for customer to run in their cloud environment to grant us access to their GCP environment. name: cs-getcspmgcp-user-scripts outputs: - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - description: Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment. name: cs-getcspmgcp-user-scripts-attachment outputs: - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationGCPProvisionGetUserScriptResponseV1.resources.bash description: '' type: String - arguments: - description: The events to retrieve, identified by ID. isArray: true name: ids required: true description: Get events entities by ID and optionally version. name: cs-getevents outputs: - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.aid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.command_line description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.connection_direction description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.event_type description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.hidden description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.host_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.icmp_code description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.icmp_type description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.image_file_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.ipv description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.local_address description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.local_port description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.match_count description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.match_count_since_last_event description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.network_profile description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.pid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.policy_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.policy_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.protocol description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.remote_address description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.remote_port description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_action description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_description description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_family_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_group_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.status description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.timestamp description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.tree_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.aid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.command_line description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.connection_direction description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.event_type description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.hidden description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.host_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.icmp_code description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.icmp_type description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.image_file_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.ipv description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.local_address description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.local_port description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.match_count description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.match_count_since_last_event description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.network_profile description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.pid description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.policy_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.policy_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.protocol description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.remote_address description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.remote_port description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_action description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_description description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_family_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_group_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.rule_name description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.status description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.timestamp description: '' type: String - contextPath: CrowdStrike.fwmgrapiEventsResponse.resources.tree_id description: '' type: String - arguments: - description: The IDs of the rule types to retrieve. isArray: true name: ids required: true description: Get the firewall field specifications by ID. name: cs-getfirewallfields outputs: - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.options.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.options.value description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.type description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.options.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.options.value description: '' type: String - contextPath: CrowdStrike.fwmgrapiFirewallFieldsResponse.resources.platform_fields.type description: '' type: String - arguments: - description: Policy ID. name: policy_id required: true - description: 'Cloud Provider (e.g.: aws|azure|gcp).' name: cloud_provider required: true - description: 'Cloud account ID (e.g.: AWS accountID, Azure subscriptionID).' name: account_id - description: Azure tenantID. name: azure_tenant_id - description: user IDs. isArray: true name: user_ids - description: Starting index of overall result set from which to return events. name: offset - description: The maximum records to return. [1-500]. name: limit description: For CSPM IOA events, gets list of IOA events. name: cs-getioa-events outputs: - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.id description: '' type: String - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.message description: '' type: String - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.id description: '' type: String - contextPath: CrowdStrike.registrationExternalIOAEventResponse.errors.message description: '' type: String - arguments: - description: The ids of the exclusions to retrieve. isArray: true name: ids required: true description: Get a set of IOA Exclusions by specifying their IDs. name: cs-getioa-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.cl_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.detection_json description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.ifn_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.cl_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.detection_json description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.ifn_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_name description: '' type: String - arguments: - description: Policy ID. name: policy_id required: true - description: 'Cloud Provider (e.g.: aws|azure|gcp).' name: cloud_provider required: true - description: 'Cloud account ID (e.g.: AWS accountID, Azure subscriptionID).' name: account_id - description: Azure tenantID. name: azure_tenant_id description: For CSPM IOA users, gets list of IOA users. name: cs-getioa-users outputs: - contextPath: CrowdStrike.registrationIOAUserResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationIOAUserResponse.errors.id description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.errors.message description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.resources.user_id description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.resources.user_name description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationIOAUserResponse.errors.id description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.errors.message description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.resources.user_id description: '' type: String - contextPath: CrowdStrike.registrationIOAUserResponse.resources.user_name description: '' type: String - arguments: - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: type_ required: true - description: The string representation of the indicator. name: value required: true description: ' DEPRECATED Use the new IOC Management endpoint (GET /iocs/entities/indicators/v1). Get an IOC by providing a type and value.' name: cs-getioc outputs: - contextPath: CrowdStrike.apiMsaReplyIOC.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.batch_id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.description description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_days description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.policy description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.share_level description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.source description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.type description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.value description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.batch_id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.description description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_days description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.policy description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.share_level description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.source description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.type description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.value description: '' type: String - arguments: - description: The ids of the exclusions to retrieve. isArray: true name: ids required: true description: Get a set of ML Exclusions by specifying their IDs. name: cs-getml-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: The IDs of the entities. isArray: true name: ids required: true description: Get pattern severities by ID. name: cs-getpatterns outputs: - contextPath: CrowdStrike.apiPatternsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiPatternsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.resources.severity description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiPatternsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiPatternsResponse.resources.severity description: '' type: String - arguments: - description: The IDs of the platforms to retrieve. isArray: true name: ids required: true description: Get platforms by ID, e.g., windows or mac or droid. name: cs-getplatforms outputs: - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.resources.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPlatformsResponse.resources.label description: '' type: String - arguments: - description: The IDs of the entities. isArray: true name: ids required: true description: Get platforms by ID. name: cs-getplatforms-mixin0 outputs: - contextPath: CrowdStrike.apiPlatformsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiPlatformsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.resources.label description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiPlatformsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiPlatformsResponse.resources.label description: '' type: String - arguments: - description: The policy container(s) to retrieve, identified by policy ID. isArray: true name: ids required: true description: Get policy container entities by policy ID. name: cs-getpolicycontainers outputs: - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.default_inbound description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.default_outbound description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.enforce description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.is_default_policy description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.platform_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.policy_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.test_mode description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.tracking description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.default_inbound description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.default_outbound description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.enforce description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.is_default_policy description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.platform_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.policy_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.test_mode description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiPolicyContainersResponse.resources.tracking description: '' type: String - arguments: - description: The IDs of the RTR Policies to return. isArray: true name: ids required: true description: Retrieve a set of Response Policies by specifying their IDs. name: cs-getrt-response-policies outputs: - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: The IDs of the rule groups to retrieve. isArray: true name: ids required: true description: Get rule group entities by ID. These groups do not contain their rule entites, just the rule IDs in precedence order. name: cs-getrulegroups outputs: - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.tracking description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRuleGroupsResponse.resources.tracking description: '' type: String - arguments: - description: The IDs of the entities. isArray: true name: ids required: true description: Get rule groups by ID. name: cs-getrulegroups-mixin0 outputs: - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.action_label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.action_label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.version description: '' type: Number - arguments: - description: The rules to retrieve, identified by ID. isArray: true name: ids required: true description: Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string). name: cs-getrules outputs: - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.action description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.address_family description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.direction description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.family description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.final_value description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.type description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.value description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_address.address description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_address.netmask description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_port.end description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_port.start description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.protocol description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_address.address description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_address.netmask description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_port.end description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_port.start description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.version description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.action description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.address_family description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.direction description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.family description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.final_value description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.label description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.type description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.fields.value description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_address.address description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_address.netmask description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_port.end description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.local_port.start description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.protocol description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_address.address description: '' type: String - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_address.netmask description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_port.end description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.remote_port.start description: '' type: Number - contextPath: CrowdStrike.fwmgrapiRulesResponse.resources.version description: '' type: Number - arguments: - description: The IDs of the entities. isArray: true name: ids required: true description: 'Get rules by ID and optionally version in the following format: `ID[:version]`. The max number of IDs is constrained by URL size.' name: cs-getrules-mixin0 outputs: - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - arguments: - description: '' isArray: true name: api_rulesgetrequestv1_ids required: true description: 'Get rules by ID and optionally version in the following format: `ID[:version]`.' name: cs-getrulesget outputs: - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - arguments: - description: The IDs of the entities. isArray: true name: ids required: true description: Get rule types by ID. name: cs-getruletypes outputs: - contextPath: CrowdStrike.apiRuleTypesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.channel description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.resources.disposition_map.id description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.resources.disposition_map.label description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.fields.name description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.fields.value description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.long_desc description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.released description: '' type: Boolean - contextPath: CrowdStrike.apiRuleTypesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.channel description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.resources.disposition_map.id description: '' type: Number - contextPath: CrowdStrike.apiRuleTypesResponse.resources.disposition_map.label description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.fields.name description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.fields.value description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.long_desc description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleTypesResponse.resources.released description: '' type: Boolean - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. name: user_uuid required: true - description: '' isArray: true name: domain_roleids_roleids required: true description: Assign one or more roles to a user. name: cs-grant-user-role-ids outputs: - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. Offset and After ms are mutually exclusive. If none provided then scrolling will be used by default. name: offset - description: The maximum records to return. name: limit - auto: PREDEFINED description: The sort expression that should be used to sort the results. name: sort predefined: - action - applied_globally - metadata.av_hits - metadata.company_name.raw - created_by - created_on - expiration - expired - metadata.filename.raw - modified_by - modified_on - metadata.original_filename.raw - metadata.product_name.raw - metadata.product_version - severity_number - source - type - value description: Get Combined for Indicators. name: cs-indicatorcombinedv1 outputs: - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - arguments: - description: The username. name: X_CS_USERNAME - description: Whether to submit to retrodetects. name: retrodetects - description: Set to true to ignore warnings and add all IOCs. name: ignore_warnings - description: '' name: api_indicatorcreatereqsv1_comment - description: '' isArray: true name: api_indicatorcreatereqsv1_indicators required: true description: Create Indicators. name: cs-indicatorcreatev1 - arguments: - description: The FQL expression to delete Indicators in bulk. If both 'filter' and 'ids' are provided, then filter takes precedence and ignores ids. name: filter_ - description: The ids of the Indicators to delete. If both 'filter' and 'ids' are provided, then filter takes precedence and ignores ids. isArray: true name: ids - description: The comment why these indicators were deleted. name: comment description: Delete Indicators by ids. name: cs-indicatordeletev1 outputs: - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of the Indicators to retrieve. isArray: true name: ids required: true description: Get Indicators by ids. name: cs-indicatorgetv1 outputs: - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. Offset and After ms are mutually exclusive. If none provided then scrolling will be used by default. name: offset - description: The maximum records to return. name: limit - auto: PREDEFINED description: The sort expression that should be used to sort the results. name: sort predefined: - action - applied_globally - metadata.av_hits - metadata.company_name.raw - created_by - created_on - expiration - expired - metadata.filename.raw - modified_by - modified_on - metadata.original_filename.raw - metadata.product_name.raw - metadata.product_version - severity_number - source - type - value description: Search for Indicators. name: cs-indicatorsearchv1 outputs: - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorQueryRespV1.errors.message description: '' type: String - arguments: - description: The username. name: X_CS_USERNAME - description: Whether to submit to retrodetects. name: retrodetects - description: Set to true to ignore warnings and add all IOCs. name: ignore_warnings - description: api_indicatorupdatereqsv1_bulk_update action. name: api_indicatorupdatereqsv1_bulk_update_action - description: api_indicatorupdatereqsv1_bulk_update applied_globally. name: api_indicatorupdatereqsv1_bulk_update_applied_globally - description: api_indicatorupdatereqsv1_bulk_update description. name: api_indicatorupdatereqsv1_bulk_update_description - description: api_indicatorupdatereqsv1_bulk_update expiration. name: api_indicatorupdatereqsv1_bulk_update_expiration - description: api_indicatorupdatereqsv1_bulk_update filter. name: api_indicatorupdatereqsv1_bulk_update_filter - description: api_indicatorupdatereqsv1_bulk_update host_groups. name: api_indicatorupdatereqsv1_bulk_update_host_groups - description: api_indicatorupdatereqsv1_bulk_update mobile_action. name: api_indicatorupdatereqsv1_bulk_update_mobile_action - description: api_indicatorupdatereqsv1_bulk_update platforms. name: api_indicatorupdatereqsv1_bulk_update_platforms - description: api_indicatorupdatereqsv1_bulk_update severity. name: api_indicatorupdatereqsv1_bulk_update_severity - description: api_indicatorupdatereqsv1_bulk_update source. name: api_indicatorupdatereqsv1_bulk_update_source - description: api_indicatorupdatereqsv1_bulk_update tags. name: api_indicatorupdatereqsv1_bulk_update_tags - description: '' name: api_indicatorupdatereqsv1_comment - description: '' isArray: true name: api_indicatorupdatereqsv1_indicators required: true description: Update Indicators. name: cs-indicatorupdatev1 outputs: - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiIndicatorRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expiration description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.expired description: '' type: Boolean - contextPath: CrowdStrike.apiIndicatorRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.mobile_action description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.severity description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.source description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.type description: '' type: String - contextPath: CrowdStrike.apiIndicatorRespV1.resources.value description: '' type: String - arguments: - description: 'Label that identifies your connection. Max: 32 alphanumeric characters (a-z, A-Z, 0-9).' name: appId required: true - description: 'Format for streaming events. Valid values: json, flatjson.' name: format description: Discover all event streams in your environment. name: cs-list-available-streamso-auth2 outputs: - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.dataFeedURL description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.refreshActiveSessionInterval description: '' type: Number - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.refreshActiveSessionURL description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.dataFeedURL description: '' type: String - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.refreshActiveSessionInterval description: '' type: Number - contextPath: CrowdStrike.maindiscoveryResponseV2.resources.refreshActiveSessionURL description: '' type: String - arguments: - description: The API client ID to authenticate your API requests. For information on generating API clients, see [API documentation inside Falcon](https://falcon.crowdstrike.com/support/documentation/1/crowdstrike-api-introduction-for-developers). name: client_id required: true - description: The API client secret to authenticate your API requests. For information on generating API clients, see [API documentation inside Falcon](https://falcon.crowdstrike.com/support/documentation/1/crowdstrike-api-introduction-for-developers). name: client_secret required: true - description: For MSSP Master CIDs, optionally lock the token to act on behalf of this member CID. name: member_cid description: Generate an OAuth2 access token. name: cs-oauth2-access-token - arguments: - description: 'The OAuth2 access token you want to revoke. Include your API client ID and secret in basic auth format (`Authorization: basic encoded API client ID and secret `) in your request header.' name: token required: true description: Revoke a previously issued OAuth2 access token before the end of its standard 30-minute life . name: cs-oauth2-revoke-token outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: ClientID to use for the Service Principal associated with the customer's Azure account. name: id_ required: true description: Update an Azure service account in our system by with the user-created client_id created with the public key we've provided. name: cs-patch-cloudconnectazure-entities-clientid-v1 - arguments: - description: ClientID to use for the Service Principal associated with the customer's Azure account. name: id_ required: true - description: Tenant ID to update client ID for. Required if multiple tenants are registered. name: tenant_id description: Update an Azure service account in our system by with the user-created client_id created with the public key we've provided. name: cs-patch-cloudconnectcspmazure-entities-clientid-v1 - arguments: - description: '' isArray: true name: registration_awsaccountpatchrequest_resources required: true description: Patches a existing account in our system for a customer. name: cs-patchcspm-aws-account - arguments: - description: 'Specify one of these actions: - `contain` - This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in your [containment policy](https://falcon.crowdstrike.com/support/documentation/11/getting-started-guide#containmentpolicy) - `lift_containment`: This action lifts containment on the host, which returns its network communications to normal - `hide_host`: This action will delete a host. After the host is deleted, no new detections for that host will be reported via UI or APIs - `unhide_host`: This action will restore a host. Detection reporting will resume after the host is restored.' name: action_name required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Take various actions on the hosts in your environment. Contain or lift containment on a host. Delete or restore a host. name: cs-perform-actionv2 - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-host-group - disable - enable - remove-host-group required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Device Control Policies specified in the request. name: cs-perform-device-control-policies-action outputs: - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-host-group - disable - enable - remove-host-group required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Firewall Policies specified in the request. name: cs-perform-firewall-policies-action outputs: - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-hosts - remove-hosts required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Host Groups specified in the request. name: cs-perform-group-action outputs: - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - arguments: - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform a set of actions on one or more incidents, such as adding tags or comments or updating the incident name or description. name: cs-perform-incident-action outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-host-group - add-rule-group - disable - enable - remove-host-group - remove-rule-group required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Prevention Policies specified in the request. name: cs-perform-prevention-policies-action outputs: - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-host-group - disable - enable - remove-host-group required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Sensor Update Policies specified in the request. name: cs-perform-sensor-update-policies-action outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - auto: PREDEFINED description: The action to perform. name: action_name predefined: - add-host-group - add-rule-group - disable - enable - remove-host-group - remove-rule-group required: true - description: '' isArray: true name: msa_entityactionrequestv2_action__meters - description: '' isArray: true name: msa_entityactionrequestv2_ids required: true description: Perform the specified action on the Response Policies specified in the request. name: cs-performrt-response-policies-action outputs: - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: '' isArray: true name: registration_azureaccountcreaterequestexternalv1_resources required: true description: Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. name: cs-post-cloudconnectazure-entities-account-v1 - arguments: - description: '' isArray: true name: registration_azureaccountcreaterequestexternalv1_resources required: true description: Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. name: cs-post-cloudconnectcspmazure-entities-account-v1 - arguments: - description: List of sample sha256 ids. isArray: true name: malquery_multidownloadrequestv1_samples required: true description: Schedule samples for download. Use the result id with the /request endpoint to check if the download is ready after which you can call the /entities/samples-fetch to get the zip. name: cs-post-mal-query-entities-samples-multidownloadv1 outputs: - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - arguments: - description: malquery_externalexactsearchparametersv1_options filter_filetypes. name: malquery_externalexactsearchparametersv1_options_filter_filetypes - description: malquery_externalexactsearchparametersv1_options filter_meta. name: malquery_externalexactsearchparametersv1_options_filter_meta - description: malquery_externalexactsearchparametersv1_options limit. name: malquery_externalexactsearchparametersv1_options_limit - description: malquery_externalexactsearchparametersv1_options max_date. name: malquery_externalexactsearchparametersv1_options_max_date - description: malquery_externalexactsearchparametersv1_options max_size. name: malquery_externalexactsearchparametersv1_options_max_size - description: malquery_externalexactsearchparametersv1_options min_date. name: malquery_externalexactsearchparametersv1_options_min_date - description: malquery_externalexactsearchparametersv1_options min_size. name: malquery_externalexactsearchparametersv1_options_min_size - description: Patterns to search for. isArray: true name: malquery_externalexactsearchparametersv1_patterns required: true description: Search Falcon MalQuery for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity. You can filter results on criteria such as file type, file size and first seen date. Returns a request id which can be used with the /request endpoint. name: cs-post-mal-query-exact-searchv1 outputs: - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - arguments: - description: malquery_fuzzysearchparametersv1_options filter_meta. name: malquery_fuzzysearchparametersv1_options_filter_meta - description: malquery_fuzzysearchparametersv1_options limit. name: malquery_fuzzysearchparametersv1_options_limit - description: '' isArray: true name: malquery_fuzzysearchparametersv1_patterns required: true description: Search Falcon MalQuery quickly, but with more potential for false positives. Search for a combination of hex patterns and strings in order to identify samples based upon file content at byte level granularity. name: cs-post-mal-query-fuzzy-searchv1 outputs: - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryFuzzySearchResponse.resources.sha256 description: Sample SHA256. type: String - arguments: - description: malquery_externalhuntparametersv1_options filter_filetypes. name: malquery_externalhuntparametersv1_options_filter_filetypes - description: malquery_externalhuntparametersv1_options filter_meta. name: malquery_externalhuntparametersv1_options_filter_meta - description: malquery_externalhuntparametersv1_options limit. name: malquery_externalhuntparametersv1_options_limit - description: malquery_externalhuntparametersv1_options max_date. name: malquery_externalhuntparametersv1_options_max_date - description: malquery_externalhuntparametersv1_options max_size. name: malquery_externalhuntparametersv1_options_max_size - description: malquery_externalhuntparametersv1_options min_date. name: malquery_externalhuntparametersv1_options_min_date - description: malquery_externalhuntparametersv1_options min_size. name: malquery_externalhuntparametersv1_options_min_size - description: A YARA rule that defines your search. name: malquery_externalhuntparametersv1_yara_rule required: true description: Schedule a YARA-based search for execution. Returns a request id which can be used with the /request endpoint. name: cs-post-mal-query-huntv1 outputs: - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.errors.type description: '' type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.ignore_reason description: Reason why the resource is ignored. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.label_confidence description: Resource label confidence. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern description: Search pattern. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.pattern_type description: Search pattern type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.family description: Sample family. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filesize description: Sample size. type: Number - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.filetype description: Sample file type. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.first_seen description: Date when it was first seen. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.label description: Sample label. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.md5 description: Sample MD5. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.samples.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha1 description: Sample SHA1. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.sha256 description: Sample SHA256. type: String - contextPath: CrowdStrike.malqueryExternalQueryResponse.resources.yara_rule description: Search YARA rule. type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: '' name: domain_rulepreviewrequest_filter required: true - description: '' name: domain_rulepreviewrequest_topic required: true description: 'Preview rules notification count and distribution. This will return aggregations on: channel, count, site.' name: cs-preview-rulev1 outputs: - contextPath: CrowdStrike.domainAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.domainAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: type_ required: true - description: The string representation of the indicator. name: value required: true - description: Specify a host's ID to return only processes from that host. Get a host's ID from GET /devices/queries/devices/v1, the Falcon console, or the Streaming API. name: device_id required: true - description: The first process to return, where 0 is the latest offset. Use with the offset meter to manage pagination of results. name: limit - description: The first process to return, where 0 is the latest offset. Use with the limit meter to manage pagination of results. name: offset description: Search for processes associated with a custom IOC. name: cs-processes-ran-on outputs: - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyProcessesRanOn.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: Mode for provisioning. Allowed values are `manual` or `cloudformation`. Defaults to manual if not defined. name: mode predefined: - cloudformation - manual - description: '' isArray: true name: models_createawsaccountsv1_resources required: true description: Provision AWS Accounts by specifying details about the accounts to provision. name: cs-provisionaws-accounts - arguments: - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit - description: 'Possible order by fields: created_timestamp, updated_timestamp. Ex: ''updated_timestamp|desc''.' name: sort - description: 'FQL query to filter actions by. Possible filter properties are: [id cid user_uuid rule_id type frequency recipients status created_timestamp updated_timestamp].' name: filter_ - description: Free text search across all indexed fields. name: q description: Query actions based on provided criteria. Use the IDs from this response to get the action entities on GET /entities/actions/v1. name: cs-query-actionsv1 outputs: - contextPath: CrowdStrike.domainQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueryResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueryResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message_key description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve allowlist tickets that match the provided filter criteria with scrolling enabled. name: cs-query-allow-list-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset - description: The maximum records to return. [1-500]. name: limit - auto: PREDEFINED description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort predefined: - timestamp.asc - timestamp.desc description: Search for behaviors by providing an FQL filter, sorting, and paging details. name: cs-query-behaviors outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve block listtickets that match the provided filter criteria with scrolling enabled. name: cs-query-block-list-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Query for customers linked as children. name: cs-query-children outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Device Control Policies in your environment by providing an FQL filter and paging details. Returns a set of Device Control Policies which match the filter criteria. name: cs-query-combined-device-control-policies outputs: - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: The ID of the Device Control Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combined-device-control-policy-members outputs: - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Firewall Policies in your environment by providing an FQL filter and paging details. Returns a set of Firewall Policies which match the filter criteria. name: cs-query-combined-firewall-policies outputs: - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - arguments: - description: The ID of the Firewall Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combined-firewall-policy-members outputs: - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - arguments: - description: The ID of the Host Group to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Host Group in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combined-group-members outputs: - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesHostGroupMembersV1.resources.system_product_name description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - group_type.asc - group_type.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc description: Search for Host Groups in your environment by providing an FQL filter and paging details. Returns a set of Host Groups which match the filter criteria. name: cs-query-combined-host-groups outputs: - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Prevention Policies in your environment by providing an FQL filter and paging details. Returns a set of Prevention Policies which match the filter criteria. name: cs-query-combined-prevention-policies outputs: - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: The ID of the Prevention Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combined-prevention-policy-members outputs: - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - arguments: - auto: PREDEFINED description: The platform to return builds for. name: platform predefined: - linux - mac - windows description: Retrieve available builds for use with Sensor Update Policies. name: cs-query-combined-sensor-update-builds outputs: - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.resources.build description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.resources.platform description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.resources.build description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdateBuildsV1.resources.platform description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria. name: cs-query-combined-sensor-update-policies outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria. name: cs-query-combined-sensor-update-policiesv2 outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - arguments: - description: The ID of the Sensor Update Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combined-sensor-update-policy-members outputs: - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Response Policies in your environment by providing an FQL filter and paging details. Returns a set of Response Policies which match the filter criteria. name: cs-query-combinedrt-response-policies outputs: - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: The ID of the Response policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Response policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. name: cs-query-combinedrt-response-policy-members outputs: - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_load_flags description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_local_time description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.agent_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.bios_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.build_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cid description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_base description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_build description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.config_id_platform description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.cpu_signature description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.detection_suppression_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.device_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.email description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.external_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.first_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.group_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.host_hidden_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.instance_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_login_user description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.last_seen description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.local_ip description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.mac_address description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.machine_domain description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.major_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.minor_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.os_version description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.platform_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_host_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_hostname description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip4 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_ip6 description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_namespace description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pod_service_account_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.pointer_size description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied description: '' type: Boolean - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.applied_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.assigned_date description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.policy_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.rule_set_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.settings_hash description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.policies.uninstall_protection description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.product_type_desc description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.provision_status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.reduced_functionality_mode description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.release_group description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.serial_number description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_major description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_pack_minor description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.service_provider_account_id description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.site_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.slow_changing_modified_timestamp description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.status description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_manufacturer description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.system_product_name description: '' type: String - contextPath: CrowdStrike.responsesPolicyMembersRespV1.resources.zone_group description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve DetectionsIds that match the provided FQL filter, criteria with scrolling enabled. name: cs-query-detection-ids-by-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The first detection to return, where `0` is the latest detection. Use with the `limit` meter to manage pagination of results. name: offset - description: 'The maximum number of detections to return in this response (default: 9999; max: 9999). Use with the `offset` meter to manage pagination of results.' name: limit - description: 'Sort detections using these options: - `first_behavior`: Timestamp of the first behavior associated with this detection - `last_behavior`: Timestamp of the last behavior associated with this detection - `max_severity`: Highest severity of the behaviors associated with this detection - `max_confidence`: Highest confidence of the behaviors associated with this detection - `adversary_id`: ID of the adversary associated with this detection, if any - `devices.hostname`: Hostname of the host where this detection was detected Sort either `asc` (ascending) or `desc` (descending). For example: `last_behavior|asc`.' name: sort - description: 'Filter detections using a query in Falcon Query Language (FQL) An asterisk wildcard ` ` includes all results. Common filter options include: - `status` - `device.device_id` - `max_severity` The full list of valid filter options is extensive. Review it in our [documentation inside the Falcon console](https://falcon.crowdstrike.com/support/documentation/2/query-api-reference#detections_fql).' name: filter_ - description: Search all detection metadata for the provided string. name: q description: Search for detection IDs that match a given query. name: cs-query-detects outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Device Control Policies in your environment by providing an FQL filter and paging details. Returns a set of Device Control Policy IDs which match the filter criteria. name: cs-query-device-control-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Device Control Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-query-device-control-policy-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by (e.g. status.desc or hostname.asc). name: sort - description: The filter expression that should be used to limit the results. name: filter_ description: Search for hosts in your environment by platform, hostname, IP, and other criteria. name: cs-query-devices-by-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The offset to page from, for the next result set. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by (e.g. status.desc or hostname.asc). name: sort - description: The filter expression that should be used to limit the results. name: filter_ description: Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit). name: cs-query-devices-by-filter-scroll outputs: - contextPath: CrowdStrike.domainDeviceResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainDeviceResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainDeviceResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainDeviceResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainDeviceResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainDeviceResponse.errors.message description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve escalation tickets that match the provided filter criteria with scrolling enabled. name: cs-query-escalations-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Firewall Policies in your environment by providing an FQL filter and paging details. Returns a set of Firewall Policy IDs which match the filter criteria. name: cs-query-firewall-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Firewall Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-query-firewall-policy-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Host Group to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Host Group in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-query-group-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by (e.g. status.desc or hostname.asc). name: sort - description: The filter expression that should be used to limit the results. name: filter_ description: Retrieve hidden hosts that match the provided filter criteria. name: cs-query-hidden-devices outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - group_type.asc - group_type.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc description: Search for Host Groups in your environment by providing an FQL filter and paging details. Returns a set of Host Group IDs which match the filter criteria. name: cs-query-host-groups outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve incidents that match the provided filter criteria with scrolling enabled. name: cs-query-incident-ids-by-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort predefined: - assigned_to.asc - assigned_to.desc - assigned_to_name.asc - assigned_to_name.desc - end.asc - end.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - sort_score.asc - sort_score.desc - start.asc - start.desc - state.asc - state.desc - status.asc - status.desc - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset - description: The maximum records to return. [1-500]. name: limit description: Search for incidents by providing an FQL filter, sorting, and paging details. name: cs-query-incidents outputs: - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaIncidentQueryResponse.errors.message description: '' type: String - arguments: - description: Set the starting row number to return actors from. Defaults to 0. name: offset - description: Set the number of actors to return. The value must be between 1 and 5000. name: limit - description: 'Order fields in ascending or descending order. Ex: created_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: actors, actors.id, actors.name, actors.slug, actors.url, created_date, description, id, last_modified_date, motivations, motivations.id, motivations.slug, motivations.value, name, name.raw, short_description, slug, sub_type, sub_type.id, sub_type.name, sub_type.slug, tags, tags.id, tags.slug, tags.value, target_countries, target_countries.id, target_countries.slug, target_countries.value, target_industries, target_industries.id, target_industries.slug, target_industries.value, type, type.id, type.name, type.slug, url.' name: filter_ - description: Perform a generic substring search across all fields. name: q - description: 'The fields to return, or a predefined set of fields in the form of the collection name surrounded by two underscores like: \_\_\ collection\ \_\_. Ex: slug \_\_full\_\_. Defaults to \_\_basic\_\_.' isArray: true name: fields description: Get info about actors that match provided FQL filters. name: cs-query-intel-actor-entities outputs: - contextPath: CrowdStrike.domainActorsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.actor_type description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.first_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.known_as description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.last_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.origins.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.origins.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.url description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.actor_type description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.first_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.known_as description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.last_activity_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainActorsResponse.resources.origins.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.origins.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.origins.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainActorsResponse.resources.url description: '' type: String - arguments: - description: Set the starting row number to return actors IDs from. Defaults to 0. name: offset - description: Set the number of actor IDs to return. The value must be between 1 and 5000. name: limit - description: 'Order fields in ascending or descending order. Ex: created_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: actors, actors.id, actors.name, actors.slug, actors.url, created_date, description, id, last_modified_date, motivations, motivations.id, motivations.slug, motivations.value, name, name.raw, short_description, slug, sub_type, sub_type.id, sub_type.name, sub_type.slug, tags, tags.id, tags.slug, tags.value, target_countries, target_countries.id, target_countries.slug, target_countries.value, target_industries, target_industries.id, target_industries.slug, target_industries.value, type, type.id, type.name, type.slug, url.' name: filter_ - description: Perform a generic substring search across all fields. name: q description: Get actor IDs that match provided FQL filters. name: cs-query-intel-actor-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Set the starting row number to return indicators from. Defaults to 0. name: offset - description: Set the number of indicators to return. The number must be between 1 and 50000. name: limit - description: 'Order fields in ascending or descending order. Ex: published_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: _marker, actors, deleted, domain_types, id, indicator, ip_address_types, kill_chains, labels, labels.created_on, labels.last_valid_on, labels.name, last_updated, malicious_confidence, malware_families, published_date, reports, targets, threat_types, type, vulnerabilities.' name: filter_ - description: Perform a generic substring search across all fields. name: q - description: If true, include both published and deleted indicators in the response. Defaults to false. name: include_deleted description: Get info about indicators that match provided FQL filters. name: cs-query-intel-indicator-entities outputs: - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.code description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.message description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources._marker description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.created_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.last_valid_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.name description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.last_updated description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.malicious_confidence description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.published_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.created_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.last_valid_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.type description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.type description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.code description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.errors.message description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources._marker description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.created_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.last_valid_on description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.labels.name description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.last_updated description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.malicious_confidence description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.published_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.created_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.id description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.indicator description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.last_valid_date description: '' type: Number - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.relations.type description: '' type: String - contextPath: CrowdStrike.domainPublicIndicatorsV3Response.resources.type description: '' type: String - arguments: - description: Set the starting row number to return indicator IDs from. Defaults to 0. name: offset - description: Set the number of indicator IDs to return. The number must be between 1 and 50000. name: limit - description: 'Order fields in ascending or descending order. Ex: published_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: _marker, actors, deleted, domain_types, id, indicator, ip_address_types, kill_chains, labels, labels.created_on, labels.last_valid_on, labels.name, last_updated, malicious_confidence, malware_families, published_date, reports, targets, threat_types, type, vulnerabilities.' name: filter_ - description: Perform a generic substring search across all fields. name: q - description: If true, include both published and deleted indicators in the response. Defaults to false. name: include_deleted description: Get indicators IDs that match provided FQL filters. name: cs-query-intel-indicator-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Set the starting row number to return reports from. Defaults to 0. name: offset - description: Set the number of reports to return. The value must be between 1 and 5000. name: limit - description: 'Order fields in ascending or descending order. Ex: created_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: actors, actors.id, actors.name, actors.slug, actors.url, created_date, description, id, last_modified_date, motivations, motivations.id, motivations.slug, motivations.value, name, name.raw, short_description, slug, sub_type, sub_type.id, sub_type.name, sub_type.slug, tags, tags.id, tags.slug, tags.value, target_countries, target_countries.id, target_countries.slug, target_countries.value, target_industries, target_industries.id, target_industries.slug, target_industries.value, type, type.id, type.name, type.slug, url.' name: filter_ - description: Perform a generic substring search across all fields. name: q - description: 'The fields to return, or a predefined set of fields in the form of the collection name surrounded by two underscores like: \_\_\ collection\ \_\_. Ex: slug \_\_full\_\_. Defaults to \_\_basic\_\_.' isArray: true name: fields description: Get info about reports that match provided FQL filters. name: cs-query-intel-report-entities outputs: - contextPath: CrowdStrike.domainNewsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.actors.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.actors.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.tags.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.active description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.actors.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.actors.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.actors.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.attachments.url description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.created_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.entitlements.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.last_modified_date description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.motivations.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.notify_users description: '' type: Boolean - contextPath: CrowdStrike.domainNewsResponse.resources.rich_text_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.short_description description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.tags.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.tags.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_countries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.id description: '' type: Number - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.name description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.slug description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.target_industries.value description: '' type: String - contextPath: CrowdStrike.domainNewsResponse.resources.url description: '' type: String - arguments: - description: Set the starting row number to return report IDs from. Defaults to 0. name: offset - description: Set the number of report IDs to return. The value must be between 1 and 5000. name: limit - description: 'Order fields in ascending or descending order. Ex: created_date|asc.' name: sort - description: 'Filter your query by specifying FQL filter meters. Filter meters include: actors, actors.id, actors.name, actors.slug, actors.url, created_date, description, id, last_modified_date, motivations, motivations.id, motivations.slug, motivations.value, name, name.raw, short_description, slug, sub_type, sub_type.id, sub_type.name, sub_type.slug, tags, tags.id, tags.slug, tags.value, target_countries, target_countries.id, target_countries.slug, target_countries.value, target_industries, target_industries.id, target_industries.slug, target_industries.value, type, type.id, type.name, type.slug, url.' name: filter_ - description: Perform a generic substring search across all fields. name: q description: Get report IDs that match provided FQL filters. name: cs-query-intel-report-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Set the starting row number to return reports from. Defaults to 0. name: offset - description: The number of rule IDs to return. Defaults to 10. name: limit - description: 'Order fields in ascending or descending order. Ex: created_date|asc.' name: sort - description: Search by rule title. isArray: true name: name - description: 'The rule news report type. Accepted values: snort-suricata-master snort-suricata-update snort-suricata-changelog yara-master yara-update yara-changelog common-event-format netwitness.' name: type_ required: true - description: Substring match on description field. isArray: true name: description - description: Search for rule tags. isArray: true name: tags - description: Filter results to those created on or after a certain date. name: min_created_date - description: Filter results to those created on or before a certain date. name: max_created_date - description: Perform a generic substring search across all fields. name: q description: Search for rule IDs that match provided filter criteria. name: cs-query-intel-rule-ids outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit - description: 'Possible order by fields: created_date, updated_date. Ex: ''updated_date|desc''.' name: sort - description: 'FQL query to filter notifications by. Possible filter properties are: [id cid user_uuid status rule_id rule_name rule_topic rule_priority item_type created_date updated_date].' name: filter_ - description: Free text search across all indexed fields. name: q description: Query notifications based on provided criteria. Use the IDs from this response to get the notification entities on GET /entities/notifications/v1 or GET /entities/notifications-detailed/v1. name: cs-query-notificationsv1 outputs: - contextPath: CrowdStrike.domainQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueryResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueryResponse.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueryResponse.errors.message_key description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Prevention Policies in your environment by providing an FQL filter and paging details. Returns a set of Prevention Policy IDs which match the filter criteria. name: cs-query-prevention-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Prevention Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-query-prevention-policy-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The maximum records to return. [1-500]. name: limit - description: The property to sort on, followed by a dot (.), followed by the sort direction, either "asc" or "desc". name: sort - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset description: Retrieve remediation tickets that match the provided filter criteria with scrolling enabled. name: cs-query-remediations-filter outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: The offset to start retrieving reports from. name: offset - description: 'Maximum number of report IDs to return. Max: 5000.' name: limit - description: 'Sort order: `asc` or `desc`.' name: sort description: Find sandbox reports by providing an FQL filter and paging details. Returns a set of report IDs that match your criteria. name: cs-query-reports outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: User Group ID to fetch MSSP role for. name: user_group_id - description: CID Group ID to fetch MSSP role for. name: cid_group_id - description: Role ID to fetch MSSP role for. name: role_id - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Query MSSP Role assignment. At least one of CID Group ID or User Group ID should also be provided. Role ID is optional. name: cs-query-roles outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit - description: 'Possible order by fields: created_timestamp, last_updated_timestamp. Ex: ''last_updated_timestamp|desc''.' name: sort - description: 'FQL query to filter rules by. Possible filter properties are: [id cid user_uuid topic priority permissions filter status created_timestamp last_updated_timestamp].' name: filter_ - description: Free text search across all indexed fields. name: q description: Query monitoring rules based on provided criteria. Use the IDs from this response to fetch the rules on /entities/rules/v1. name: cs-query-rulesv1 outputs: - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRuleQueryResponseV1.errors.message_key description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: '' isArray: true name: samplestore_querysamplesrequest_sha256s description: Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200. name: cs-query-samplev1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - auto: PREDEFINED description: The property to sort by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policy IDs which match the filter criteria. name: cs-query-sensor-update-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Sensor Update Policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-query-sensor-update-policy-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-500]. name: limit - auto: PREDEFINED description: The sort expression that should be used to sort the results. name: sort predefined: - applied_globally.asc - applied_globally.desc - created_by.asc - created_by.desc - created_on.asc - created_on.desc - last_modified.asc - last_modified.desc - modified_by.asc - modified_by.desc - value.asc - value.desc description: Search for sensor visibility exclusions. name: cs-query-sensor-visibility-exclusionsv1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: The offset to start retrieving submissions from. name: offset - description: 'Maximum number of submission IDs to return. Max: 5000.' name: limit - description: 'Sort order: `asc` or `desc`.' name: sort description: Find submission IDs for uploaded files by providing an FQL filter and paging details. Returns a set of submission IDs that match your criteria. name: cs-query-submissions outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Optional filter and sort criteria in the form of an FQL query. For more information about FQL queries, see [our FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: The offset to start retrieving submissions from. name: offset - description: 'Maximum number of volume IDs to return. Max: 5000.' name: limit - description: 'Sort order: `asc` or `desc`.' name: sort description: Find IDs for submitted scans by providing an FQL filter and paging details. Returns a set of volume IDs that match your criteria. name: cs-query-submissions-mixin0 outputs: - contextPath: CrowdStrike.mlscannerQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.message description: '' type: String - arguments: - description: User UUID to lookup associated user group ID. name: user_uuid required: true - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Query User Group member by User UUID. name: cs-query-user-group-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Name to lookup groups for. name: name - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - name - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Query User Groups. name: cs-query-user-groups outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: A pagination token used with the `limit` meter to manage pagination of results. On your first request, don't provide an `after` token. On subsequent requests, provide the `after` token from the previous response to continue from that place in the results. name: after - description: 'The number of items to return in this response (default: 100, max: 400). Use with the after meter to manage pagination of results.' name: limit - description: 'Sort vulnerabilities by their properties. Common sort options include: ul li created_timestamp|desc /li li closed_timestamp|asc /li /ul.' name: sort - description: 'Filter items using a query in Falcon Query Language (FQL). Wildcards are unsupported. Common filter options include: ul li created_timestamp: ''2019-11-25T22:36:12Z'' /li li closed_timestamp: ''2019-11-25T22:36:12Z'' /li li aid:''8e7656b27d8c49a34a1af416424d6231'' /li /ul.' name: filter_ required: true description: Search for Vulnerabilities in your environment by providing an FQL filter and paging details. Returns a set of Vulnerability IDs which match the filter criteria. name: cs-query-vulnerabilities outputs: - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainSPAPIQueryVulnerabilitiesResponse.errors.message description: '' type: String - arguments: - description: The maximum records to return. [1-500]. Defaults to 100. name: limit - description: The offset to start retrieving records from. name: offset - description: The property to sort by (e.g. alias.desc or state.asc). name: sort - description: The filter expression that should be used to limit the results. name: filter_ description: Search for provisioned AWS Accounts by providing an FQL filter and paging details. Returns a set of AWS accounts which match the filter criteria. name: cs-queryaws-accounts outputs: - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - arguments: - description: The maximum records to return. [1-500]. Defaults to 100. name: limit - description: The offset to start retrieving records from. name: offset - description: The property to sort by (e.g. alias.desc or state.asc). name: sort - description: The filter expression that should be used to limit the results. name: filter_ description: Search for provisioned AWS Accounts by providing an FQL filter and paging details. Returns a set of AWS account IDs which match the filter criteria. name: cs-queryaws-accounts-fori-ds outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: CID to lookup associated CID group ID. name: cid required: true - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - description: Starting index of overall result set from which to return id. name: offset - description: Number of ids to return. name: limit description: Query a CID Groups members by associated CID. name: cs-querycid-group-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Name to lookup groups for. name: name - auto: PREDEFINED description: The sort expression used to sort the results. name: sort predefined: - last_modified_timestamp - name - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Query CID Groups. name: cs-querycid-groups outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: 'Possible order by fields:.' name: sort - description: 'FQL query specifying the filter meters. Filter term criteria: enabled, platform, name, description, etc TODO. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields, plus TODO. name: q - description: Starting index of overall result set from which to return ids. name: offset - description: A pagination token used with the `limit` meter to manage pagination of results. On your first request, don't provide an `after` token. On subsequent requests, provide the `after` token from the previous response to continue from that place in the results. name: after - description: Number of ids to return. name: limit description: Find all event IDs matching the query with filter. name: cs-queryevents outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - description: Get fields configuration for this platform. name: platform_id - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Get the firewall field specification IDs for the provided platform. name: cs-queryfirewallfields outputs: - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.message description: '' type: String - arguments: - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: types - description: The string representation of the indicator. name: values - description: Find custom IOCs created after this time (RFC-3339 timestamp). name: from_expiration_timestamp - description: Find custom IOCs created before this time (RFC-3339 timestamp). name: to_expiration_timestamp - description: '\ndetect: Find custom IOCs that produce notifications\n\nnone: Find custom IOCs the particular indicator has been detected on a host. This is equivalent to turning the indicator off. ' name: policies - description: The source where this indicator originated. This can be used for tracking where this indicator was defined. Limit 200 characters. name: sources - description: The level at which the indicator will be shared. Currently only red share level (not shared) is supported, indicating that the IOC isn't shared with other FH customers. name: share_levels - description: created_by. name: created_by - description: The user or API client who deleted the custom IOC. name: deleted_by - description: 'true: Include deleted IOCs false: Don''t include deleted IOCs (default).' name: include_deleted description: ' DEPRECATED Use the new IOC Management endpoint (GET /iocs/queries/indicators/v1). Search the custom IOCs in your customer account.' name: cs-queryio-cs outputs: - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOCIDs.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-500]. name: limit - auto: PREDEFINED description: The sort expression that should be used to sort the results. name: sort predefined: - applied_globally.asc - applied_globally.desc - created_by.asc - created_by.desc - created_on.asc - created_on.desc - last_modified.asc - last_modified.desc - modified_by.asc - modified_by.desc - name.asc - name.desc - pattern_id.asc - pattern_id.desc - pattern_name.asc - pattern_name.desc description: Search for IOA exclusions. name: cs-queryioa-exclusionsv1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-500]. name: limit - auto: PREDEFINED description: The sort expression that should be used to sort the results. name: sort predefined: - applied_globally.asc - applied_globally.desc - created_by.asc - created_by.desc - created_on.asc - created_on.desc - last_modified.asc - last_modified.desc - modified_by.asc - modified_by.desc - value.asc - value.desc description: Search for ML exclusions. name: cs-queryml-exclusionsv1 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Get all pattern severity IDs. name: cs-querypatterns outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Get the list of platform names. name: cs-queryplatforms outputs: - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaQueryResponse.errors.message description: '' type: String - arguments: - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Get all platform IDs. name: cs-queryplatforms-mixin0 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the policy container within which to query. name: id_ - description: 'Possible order by fields:.' name: sort - description: 'FQL query specifying the filter meters. Filter term criteria: enabled, platform, name, description, etc TODO. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields, plus TODO. name: q - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit description: Find all firewall rule IDs matching the query with filter, and return them in precedence order. name: cs-querypolicyrules outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - description: The filter expression that should be used to determine the results. name: filter_ - description: The offset of the first record to retrieve from. name: offset - description: The maximum number of records to return [1-5000]. name: limit - auto: PREDEFINED description: The property to sort results by. name: sort predefined: - created_by.asc - created_by.desc - created_timestamp.asc - created_timestamp.desc - enabled.asc - enabled.desc - modified_by.asc - modified_by.desc - modified_timestamp.asc - modified_timestamp.desc - name.asc - name.desc - platform_name.asc - platform_name.desc - precedence.asc - precedence.desc description: Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details. This returns a set of Response Policy IDs that match the given criteria. name: cs-queryrt-response-policies outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ID of the Response policy to search for members of. name: id_ - description: The filter expression that should be used to limit the results. name: filter_ - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-5000]. name: limit - description: The property to sort by. name: sort description: Search for members of a Response policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. name: cs-queryrt-response-policy-members outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: 'Possible order by fields:.' name: sort - description: 'FQL query specifying the filter meters. Filter term criteria: enabled, platform, name, description, etc TODO. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields, plus TODO. name: q - description: Starting index of overall result set from which to return ids. name: offset - description: A pagination token used with the `limit` meter to manage pagination of results. On your first request, don't provide an `after` token. On subsequent requests, provide the `after` token from the previous response to continue from that place in the results. name: after - description: Number of ids to return. name: limit description: Find all rule group IDs matching the query with filter. name: cs-queryrulegroups outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: 'Possible order by fields: {created_by, created_on, modified_by, modified_on, enabled, name, description}.' name: sort predefined: - created_by - created_on - description - enabled - modified_by - modified_on - name - description: 'FQL query specifying the filter meters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields. name: q - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Finds all rule group IDs matching the query with optional filter. name: cs-queryrulegroups-mixin0 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: 'Possible order by fields: {created_by, created_on, modified_by, modified_on, enabled, name, description}.' name: sort predefined: - created_by - created_on - description - enabled - modified_by - modified_on - name - description: 'FQL query specifying the filter meters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields. name: q - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Find all rule groups matching the query with optional filter. name: cs-queryrulegroupsfull outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: 'Possible order by fields:.' name: sort - description: 'FQL query specifying the filter meters. Filter term criteria: enabled, platform, name, description, etc TODO. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields, plus TODO. name: q - description: Starting index of overall result set from which to return ids. name: offset - description: A pagination token used with the `limit` meter to manage pagination of results. On your first request, don't provide an `after` token. On subsequent requests, provide the `after` token from the previous response to continue from that place in the results. name: after - description: Number of ids to return. name: limit description: Find all rule IDs matching the query with filter. name: cs-queryrules outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: 'Possible order by fields: {rules.ruletype_name, rules.enabled, rules.created_by, rules.current_version.name, rules.current_version.modified_by, rules.created_on, rules.current_version.description, rules.current_version.pattern_severity, rules.current_version.action_label, rules.current_version.modified_on}.' name: sort predefined: - rules.created_by - rules.created_on - rules.current_version.action_label - rules.current_version.description - rules.current_version.modified_by - rules.current_version.modified_on - rules.current_version.name - rules.current_version.pattern_severity - rules.enabled - rules.ruletype_name - description: 'FQL query specifying the filter meters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as ''2010-05-15T14:55:21.892315096Z''.' name: filter_ - description: Match query criteria, which includes all the filter string fields. name: q - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Finds all rule IDs matching the query with optional filter. name: cs-queryrules-mixin0 outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Starting index of overall result set from which to return IDs. name: offset - description: Number of IDs to return. name: limit description: Get all rule type IDs. name: cs-queryruletypes outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: Action name. Allowed value is refresh_active_stream_session. name: action_name required: true - description: 'Label that identifies your connection. Max: 32 alphanumeric characters (a-z, A-Z, 0-9).' name: appId required: true - description: Partition to request data for. name: partition required: true description: Refresh an active event stream. Use the URL shown in a GET /sensors/entities/datafeed/v2 response. name: cs-refresh-active-stream-session outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - description: Regenerate API key for docker registry integrations. name: cs-regenerateapi-key outputs: - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.resources.api_key description: '' type: String - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.code description: '' type: Number - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.id description: '' type: String - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.errors.message description: '' type: String - contextPath: CrowdStrike.k8sregRegenAPIKeyResp.resources.api_key description: '' type: String - description: List the usernames (usually an email address) for all users in your customer account. name: cs-retrieve-emails-bycid outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. isArray: true name: ids required: true description: Get info about a user. name: cs-retrieve-user outputs: - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.customer description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.firstName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.lastName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uuid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.customer description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.firstName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.lastName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uuid description: '' type: String - description: List user IDs for all users in your customer account. For more information on each user, provide the user ID to `/users/entities/user/v1`. name: cs-retrieve-useruui-ds-bycid outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: A username. This is usually the user's email address, but may vary based on your configuration. isArray: true name: uid required: true description: Get a user's ID by providing a username (usually an email address). name: cs-retrieve-useruuid outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: An optional message to append to the recorded audit log. name: requests_revealuninstalltokenv1_audit_message - description: The id of the device to reveal the token for. name: requests_revealuninstalltokenv1_device_id required: true description: Reveals an uninstall token for a specific device. To retrieve the bulk maintenance token pass the value 'MAINTENANCE' as the value for 'device_id'. name: cs-reveal-uninstall-token outputs: - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.device_id description: The device the token belongs to. type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.seed_id description: The seedID of the uninstall token. type: Number - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.uninstall_token description: The uninstall token. type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.device_id description: The device the token belongs to. type: String - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.seed_id description: The seedID of the uninstall token. type: Number - contextPath: CrowdStrike.responsesRevealUninstallTokenRespV1.resources.uninstall_token description: The uninstall token. type: String - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. name: user_uuid required: true - description: One or more role IDs to revoke. Find a role's ID from `/users/queries/roles/v1`. isArray: true name: ids required: true description: Revoke one or more roles from a user. name: cs-revoke-user-role-ids outputs: - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserRoleIDsResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: msa_aggregatequeryrequest_date_ranges required: true - description: '' name: msa_aggregatequeryrequest_field required: true - description: '' name: msa_aggregatequeryrequest_filter required: true - description: '' name: msa_aggregatequeryrequest_interval required: true - description: '' name: msa_aggregatequeryrequest_min_doc_count required: true - description: '' name: msa_aggregatequeryrequest_missing required: true - description: '' name: msa_aggregatequeryrequest_name required: true - description: '' name: msa_aggregatequeryrequest_q required: true - description: '' isArray: true name: msa_aggregatequeryrequest_ranges required: true - description: '' name: msa_aggregatequeryrequest_size required: true - description: '' name: msa_aggregatequeryrequest_sort required: true - description: '' isArray: true name: msa_aggregatequeryrequest_sub_aggregates required: true - description: '' name: msa_aggregatequeryrequest_time_zone required: true - description: '' name: msa_aggregatequeryrequest_type required: true description: Get aggregates on session data. name: cs-rtr-aggregate-sessions outputs: - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.count description: '' type: Number - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.from description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.key_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_from description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.string_to description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.to description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value description: '' type: Unknown - contextPath: CrowdStrike.msaAggregatesResponse.resources.buckets.value_as_string description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.msaAggregatesResponse.resources.sum_other_doc_count description: '' type: Number - arguments: - description: Cloud Request ID of the executed command to query. name: cloud_request_id required: true - description: Sequence ID that we want to retrieve. Command responses are chunked across sequences. name: sequence_id required: true description: Get status of an executed active-responder command on a single host. name: cs-rtr-check-active-responder-command-status outputs: - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - arguments: - description: Cloud Request ID of the executed command to query. name: cloud_request_id required: true - description: Sequence ID that we want to retrieve. Command responses are chunked across sequences. name: sequence_id required: true description: Get status of an executed RTR administrator command on a single host. name: cs-rtr-check-admin-command-status outputs: - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - arguments: - description: Cloud Request ID of the executed command to query. name: cloud_request_id required: true - description: Sequence ID that we want to retrieve. Command responses are chunked across sequences. name: sequence_id required: true description: Get status of an executed command on a single host. name: cs-rtr-check-command-status outputs: - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.base_command description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.complete description: '' type: Boolean - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.sequence_id description: '' type: Number - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stderr description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.stdout description: '' type: String - contextPath: CrowdStrike.domainStatusResponseWrapper.resources.task_id description: '' type: String - arguments: - description: put-file to upload. name: file required: true - description: File description. name: description required: true - description: File name (if different than actual file name). name: name - description: The audit log comment. name: comments_for_audit_log description: Upload a new put-file to use for the RTR `put` command. name: cs-rtr-create-put-files outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: custom-script file to upload. These should be powershell scripts. name: file - description: File description. name: description required: true - description: File name (if different than actual file name). name: name - description: The audit log comment. name: comments_for_audit_log - description: 'Permission for the custom-script. Valid permission values: - `private`, usable by only the user who uploaded it - `group`, usable by all RTR Admins - `public`, usable by all active-responders and RTR admins.' name: permission_type required: true - description: The script text that you want to use to upload. name: content - description: 'Platforms for the file. Currently supports: windows, mac, linux, . If no platform is provided, it will default to ''windows''.' isArray: true name: platform description: Upload a new custom-script to use for the RTR `runscript` command. name: cs-rtr-create-scripts outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: RTR Session file id. name: ids required: true - description: RTR Session id. name: session_id required: true description: Delete a RTR session file. name: cs-rtr-delete-file - arguments: - description: File id. name: ids required: true description: Delete a put-file based on the ID given. Can only delete one file at a time. name: cs-rtr-delete-put-files outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: RTR Session id. name: session_id required: true - description: Cloud Request ID of the executed command to query. name: cloud_request_id required: true description: Delete a queued session command. name: cs-rtr-delete-queued-session - arguments: - description: File id. name: ids required: true description: Delete a custom-script based on the ID given. Can only delete one script at a time. name: cs-rtr-delete-scripts outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: RTR Session id. name: session_id required: true description: Delete a session. name: cs-rtr-delete-session - arguments: - description: '' name: domain_commandexecuterequest_base_command required: true - description: '' name: domain_commandexecuterequest_command_string required: true - description: '' name: domain_commandexecuterequest_device_id required: true - description: '' name: domain_commandexecuterequest_id required: true - description: '' name: domain_commandexecuterequest_persist required: true - description: '' name: domain_commandexecuterequest_session_id required: true description: Execute an active responder command on a single host. name: cs-rtr-execute-active-responder-command - arguments: - description: '' name: domain_commandexecuterequest_base_command required: true - description: '' name: domain_commandexecuterequest_command_string required: true - description: '' name: domain_commandexecuterequest_device_id required: true - description: '' name: domain_commandexecuterequest_id required: true - description: '' name: domain_commandexecuterequest_persist required: true - description: '' name: domain_commandexecuterequest_session_id required: true description: Execute a RTR administrator command on a single host. name: cs-rtr-execute-admin-command - arguments: - description: '' name: domain_commandexecuterequest_base_command required: true - description: '' name: domain_commandexecuterequest_command_string required: true - description: '' name: domain_commandexecuterequest_device_id required: true - description: '' name: domain_commandexecuterequest_id required: true - description: '' name: domain_commandexecuterequest_persist required: true - description: '' name: domain_commandexecuterequest_session_id required: true description: Execute a command on a single host. name: cs-rtr-execute-command - arguments: - description: RTR Session id. name: session_id required: true - description: Extracted SHA256 (e.g. 'efa256a96af3b556cd3fc9d8b1cf587d72807d7805ced441e8149fc279db422b'). name: sha256 required: true - description: Filename to use for the archive name and the file within the archive. name: filename description: Get RTR extracted file contents for specified session and sha256. name: cs-rtr-get-extracted-file-contents - arguments: - description: File IDs. isArray: true name: ids required: true description: Get put-files based on the ID's given. These are used for the RTR `put` command. name: cs-rtr-get-put-files outputs: - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.bucket description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.comments_for_audit_log description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.content description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.description description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.file_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.name description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.path description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.permission_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_attempt_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_success_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.size description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.write_access description: '' type: Boolean - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.bucket description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.comments_for_audit_log description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.content description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.description description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.file_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.name description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.path description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.permission_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_attempt_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_success_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.size description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.write_access description: '' type: Boolean - arguments: - description: File IDs. isArray: true name: ids required: true description: Get custom-scripts based on the ID's given. These are used for the RTR `runscript` command. name: cs-rtr-get-scripts outputs: - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.bucket description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.comments_for_audit_log description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.content description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.description description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.file_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.name description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.path description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.permission_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_attempt_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_success_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.size description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.write_access description: '' type: Boolean - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.bucket description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.cid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.comments_for_audit_log description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.content description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.description description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.file_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_by_uuid description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.name description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.path description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.permission_type description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_attempt_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.run_success_count description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.sha256 description: '' type: String - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.size description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPFResponse.resources.write_access description: '' type: Boolean - arguments: - description: '' name: domain_initrequest_device_id required: true - description: '' name: domain_initrequest_origin required: true - description: '' name: domain_initrequest_queue_offline required: true description: Initialize a new session with the RTR cloud. name: cs-rtr-init-session - arguments: - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit - description: 'Sort by spec. Ex: ''date_created|asc''.' name: sort - description: "Optional filter criteria in the form of an FQL query. For more information about FQL queries, see our [FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). “user_id” can accept a special value ‘@me’ which will restrict results to records with current user’s ID." name: filter_ description: Get a list of session_ids. name: cs-rtr-list-all-sessions outputs: - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.code description: '' type: Number - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.id description: '' type: String - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.message description: '' type: String - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.code description: '' type: Number - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.id description: '' type: String - contextPath: CrowdStrike.domainListSessionsResponseMsa.errors.message description: '' type: String - arguments: - description: RTR Session id. name: session_id required: true description: Get a list of files for the specified RTR session. name: cs-rtr-list-files outputs: - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.id description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.name description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.sha256 description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.size description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.updated_at description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.id description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.name description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.session_id description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.sha256 description: '' type: String - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.size description: '' type: Number - contextPath: CrowdStrike.domainListFilesResponseWrapper.resources.updated_at description: '' type: String - arguments: - description: Optional filter criteria in the form of an FQL query. For more information about FQL queries, see our [FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit - description: 'Sort by spec. Ex: ''created_at|asc''.' name: sort description: Get a list of put-file ID's that are available to the user for the `put` command. name: cs-rtr-list-put-files outputs: - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: Get queued session metadata by session ID. name: cs-rtr-list-queued-sessions outputs: - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.base_command description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.command_string description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.created_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.deleted_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.status description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.status_text description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.updated_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.aid description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.status description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.updated_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.user_id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.base_command description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.command_string description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.created_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.deleted_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.status description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.status_text description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.Commands.updated_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.aid description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.status description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.updated_at description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.user_id description: '' type: String - contextPath: CrowdStrike.domainQueuedSessionResponseWrapper.resources.user_uuid description: '' type: String - arguments: - description: Optional filter criteria in the form of an FQL query. For more information about FQL queries, see our [FQL documentation in Falcon](https://falcon.crowdstrike.com/support/documentation/45/falcon-query-language-feature-guide). name: filter_ - description: Starting index of overall result set from which to return ids. name: offset - description: Number of ids to return. name: limit - description: 'Sort by spec. Ex: ''created_at|asc''.' name: sort description: Get a list of custom-script ID's that are available to the user for the `runscript` command. name: cs-rtr-list-scripts outputs: - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.message description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.id description: '' type: String - contextPath: CrowdStrike.binservclientMsaPutFileResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: msa_idsrequest_ids required: true description: Get session metadata by session id. name: cs-rtr-list-sessions outputs: - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.cid description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.commands_queued description: '' type: Boolean - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.device_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.duration description: '' type: Unknown - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.hostname description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.base_command description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.command_string description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.created_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.current_directory description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.id description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.session_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.updated_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.offline_queued description: '' type: Boolean - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.origin description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.platform_id description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.platform_name description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.pwd description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.updated_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.user_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.code description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.errors.message description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.cid description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.commands_queued description: '' type: Boolean - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.created_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.deleted_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.device_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.duration description: '' type: Unknown - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.hostname description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.base_command description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.cloud_request_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.command_string description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.created_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.current_directory description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.id description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.session_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.logs.updated_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.offline_queued description: '' type: Boolean - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.origin description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.platform_id description: '' type: Number - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.platform_name description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.pwd description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.updated_at description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.user_id description: '' type: String - contextPath: CrowdStrike.domainSessionResponseWrapper.resources.user_uuid description: '' type: String - arguments: - description: '' name: domain_initrequest_device_id required: true - description: '' name: domain_initrequest_origin required: true - description: '' name: domain_initrequest_queue_offline required: true description: Refresh a session timeout on a single host. name: cs-rtr-pulse-session - arguments: - description: ID to update. name: id_ required: true - description: custom-script file to upload. These should be powershell scripts. name: file - description: File description. name: description - description: File name (if different than actual file name). name: name - description: The audit log comment. name: comments_for_audit_log - description: 'Permission for the custom-script. Valid permission values: - `private`, usable by only the user who uploaded it - `group`, usable by all RTR Admins - `public`, usable by all active-responders and RTR admins.' name: permission_type - description: The script text that you want to use to upload. name: content - description: 'Platforms for the file. Currently supports: windows, mac,.' isArray: true name: platform description: Upload a new scripts to replace an existing one. name: cs-rtr-update-scripts outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: '' isArray: true name: mlscanner_samplesscanparameters_samples required: true description: Submit a volume of files for ml scanning. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute. name: cs-scan-samples outputs: - contextPath: CrowdStrike.mlscannerQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.mlscannerQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.mlscannerQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of all current prevention policies for the platform specified. The precedence will be set in the order the ids are specified. isArray: true name: requests_setpolicyprecedencereqv1_ids required: true - auto: PREDEFINED description: The name of the platform for which to set precedence. name: requests_setpolicyprecedencereqv1_platform_name predefined: - Windows - Mac - Linux required: true description: Sets the precedence of Device Control Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. name: cs-set-device-control-policies-precedence outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of all current prevention policies for the platform specified. The precedence will be set in the order the ids are specified. isArray: true name: requests_setpolicyprecedencereqv1_ids required: true - auto: PREDEFINED description: The name of the platform for which to set precedence. name: requests_setpolicyprecedencereqv1_platform_name predefined: - Windows - Mac - Linux required: true description: Sets the precedence of Firewall Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. name: cs-set-firewall-policies-precedence outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of all current prevention policies for the platform specified. The precedence will be set in the order the ids are specified. isArray: true name: requests_setpolicyprecedencereqv1_ids required: true - auto: PREDEFINED description: The name of the platform for which to set precedence. name: requests_setpolicyprecedencereqv1_platform_name predefined: - Windows - Mac - Linux required: true description: Sets the precedence of Prevention Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. name: cs-set-prevention-policies-precedence outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of all current prevention policies for the platform specified. The precedence will be set in the order the ids are specified. isArray: true name: requests_setpolicyprecedencereqv1_ids required: true - auto: PREDEFINED description: The name of the platform for which to set precedence. name: requests_setpolicyprecedencereqv1_platform_name predefined: - Windows - Mac - Linux required: true description: Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. name: cs-set-sensor-update-policies-precedence outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: The ids of all current prevention policies for the platform specified. The precedence will be set in the order the ids are specified. isArray: true name: requests_setpolicyprecedencereqv1_ids required: true - auto: PREDEFINED description: The name of the platform for which to set precedence. name: requests_setpolicyprecedencereqv1_platform_name predefined: - Windows - Mac - Linux required: true description: Sets the precedence of Response Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. name: cs-setrt-response-policies-precedence outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: falconx_submissionparametersv1_sandbox - description: '' isArray: true name: falconx_submissionparametersv1_user_tags description: Submit an uploaded file or a URL for sandbox analysis. Time required for analysis varies but is usually less than 15 minutes. name: cs-submit outputs: - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.action_script description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.command_line description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.document_password description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.enable_tor description: '' type: Boolean - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_date description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_time description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.url description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.state description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_uuid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.code description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.errors.message description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.cid description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.origin description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.action_script description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.command_line description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.document_password description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.enable_tor description: '' type: Boolean - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.environment_id description: '' type: Number - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.sha256 description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.submit_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_date description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.system_time description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.sandbox.url description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.state description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_id description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_name description: '' type: String - contextPath: CrowdStrike.falconxSubmissionV1Response.resources.user_uuid description: '' type: String - arguments: - description: The token's expiration time (RFC-3339). Null, if the token never expires. name: api_tokencreaterequestv1_expires_timestamp - description: The token label. name: api_tokencreaterequestv1_label - description: The token type. name: api_tokencreaterequestv1_type description: Creates a token. name: cs-tokenscreate - arguments: - description: The token ids to delete. isArray: true name: ids required: true description: Deletes a token immediately. To revoke a token, use PATCH /installation-tokens/entities/tokens/v1 instead. name: cs-tokensdelete outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: The offset to start retrieving records from. name: offset - description: The maximum records to return. [1-1000]. Defaults to 50. name: limit - description: The property to sort by (e.g. created_timestamp.desc). name: sort - description: The filter expression that should be used to limit the results (e.g., `status:'valid'`). name: filter_ description: Search for tokens by providing an FQL filter and paging details. name: cs-tokensquery outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - description: IDs of tokens to retrieve details for. isArray: true name: ids description: Gets the details of one or more tokens by id. name: cs-tokensread outputs: - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.expires_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.label description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.last_used_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.revoked_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.status description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.type description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.value description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.expires_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.label description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.last_used_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.revoked_timestamp description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.status description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.type description: '' type: String - contextPath: CrowdStrike.apitokenDetailsResponseV1.resources.value description: '' type: String - arguments: - description: The token ids to update. isArray: true name: ids required: true - description: The token's expiration time (RFC-3339). Null, if the token never expires. name: api_tokenpatchrequestv1_expires_timestamp - description: The token label. name: api_tokenpatchrequestv1_label - description: Set to true to revoke the token, false to un-revoked it. name: api_tokenpatchrequestv1_revoked description: Updates one or more tokens. Use this endpoint to edit labels, change expiration, revoke, or restore. name: cs-tokensupdate outputs: - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaQueryResponse.errors.message description: '' type: String - arguments: - auto: PREDEFINED description: Scan Type to do. name: scan_type predefined: - cluster-refresh - dry-run - full required: true description: Triggers a dry run or a full scan of a customer's kubernetes footprint. name: cs-trigger-scan - arguments: - description: '' name: domain_updateactionrequest_frequency required: true - description: '' name: domain_updateactionrequest_id required: true - description: '' isArray: true name: domain_updateactionrequest_recipients required: true - description: '' name: domain_updateactionrequest_status required: true description: Update an action for a monitoring rule. name: cs-update-actionv1 outputs: - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.cid description: The ID of the customer who created the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.created_timestamp description: The date when the action was created. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.frequency description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.id description: The ID of the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.rule_id description: The ID of the rule on which this action is attached. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.status description: The action status. It can be either 'enabled' or 'muted'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.type description: The action type. The only type currently supported is 'email'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.updated_timestamp description: The date when the action was updated. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.user_uuid description: The UUID of the user who created the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.cid description: The ID of the customer who created the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.created_timestamp description: The date when the action was created. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.frequency description: '' type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.id description: The ID of the action. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.rule_id description: The ID of the rule on which this action is attached. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.status description: The action status. It can be either 'enabled' or 'muted'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.type description: The action type. The only type currently supported is 'email'. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.updated_timestamp description: The date when the action was updated. type: String - contextPath: CrowdStrike.domainActionEntitiesResponseV1.resources.user_uuid description: The UUID of the user who created the action. type: String - arguments: - description: '' name: domain_detectsentitiespatchrequest_assigned_to_uuid - description: '' name: domain_detectsentitiespatchrequest_comment - description: '' isArray: true name: domain_detectsentitiespatchrequest_ids - description: '' name: domain_detectsentitiespatchrequest_show_in_ui - description: '' name: domain_detectsentitiespatchrequest_status description: Modify the state, assignee, and visibility of detections. name: cs-update-detects-by-idsv2 outputs: - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.msaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.msaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatedevicecontrolpoliciesv1_resources required: true description: Update Device Control Policies by specifying the ID of the policy and details to update. name: cs-update-device-control-policies outputs: - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesDeviceControlPoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: '' name: domain_updatedevicetagsrequestv1_action required: true - description: '' isArray: true name: domain_updatedevicetagsrequestv1_device_ids required: true - description: '' isArray: true name: domain_updatedevicetagsrequestv1_tags required: true description: Append or remove one or more Falcon Grouping Tags on one or more hosts. name: cs-update-device-tags outputs: - contextPath: CrowdStrike.msaEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaEntitiesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaEntitiesResponse.errors.message description: '' type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatefirewallpoliciesv1_resources required: true description: Update Firewall Policies by specifying the ID of the policy and details to update. name: cs-update-firewall-policies outputs: - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.channel_version description: Channel file version for the policy. type: Number - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesFirewallPoliciesV1.resources.rule_set_id description: Firewall rule set id. This id combines several firewall rules and gets attached to the policy. type: String - arguments: - description: A collection of groups to update. isArray: true name: requests_updategroupsv1_resources required: true description: Update Host Groups by specifying the ID of the group and details to update. name: cs-update-host-groups outputs: - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesHostGroupsV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesHostGroupsV1.resources.name description: The name of the group. type: String - arguments: - description: The unique ID of the user who is assigned to this notification. name: domain_updatenotificationrequestv1_assigned_to_uuid required: true - description: The ID of the notifications. name: domain_updatenotificationrequestv1_id required: true - description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' name: domain_updatenotificationrequestv1_status required: true description: Update notification status or assignee. Accepts bulk requests. name: cs-update-notificationsv1 outputs: - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uid description: The email of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_username description: The name of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.assigned_to_uuid description: The unique ID of the user who is assigned to this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.created_date description: The date when the notification was generated. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.id description: The ID of the notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_date description: Timestamp when the intelligence item is considered to have been posted. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_id description: ID of the intelligence item which generated the match. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.item_type description: Type of intelligence item based on format, e.g. post, reply, botnet_config. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_id description: The ID of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_name description: The name of the rule that generated this notification. type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_priority description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.rule_topic description: '' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.status description: 'The notification status. This can be one of: new, in-progress, closed-false-positive, closed-true-positive.' type: String - contextPath: CrowdStrike.domainNotificationEntitiesResponseV1.resources.updated_date description: The date when the notification was updated. type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatepreventionpoliciesv1_resources required: true description: Update Prevention Policies by specifying the ID of the policy and details to update. name: cs-update-prevention-policies outputs: - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesPreventionPoliciesV1.resources.prevention_settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: The filter to be used for searching. name: domain_updaterulerequestv1_filter required: true - description: The rule ID to be updated. name: domain_updaterulerequestv1_id required: true - description: The name of a particular rule. name: domain_updaterulerequestv1_name required: true - description: 'The permissions for a particular rule which specifies the rule''s access by other users. Possible values: [private public].' name: domain_updaterulerequestv1_permissions required: true - description: 'The priority for a particular rule. Possible values: [low medium high].' name: domain_updaterulerequestv1_priority required: true description: Update monitoring rules. name: cs-update-rulesv1 outputs: - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.created_timestamp description: The creation time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.filter description: The FQL filter contained in a rule and used for searching. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.id description: The ID of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.name description: The name for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.permissions description: The permissions of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.priority description: The priority of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status description: The status of a rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status_message description: The detailed status message. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.topic description: The topic of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.updated_timestamp description: The last updated time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_id description: The user ID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_name description: The user name of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_uuid description: The UUID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.field description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.details.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.errors.message_key description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.created_timestamp description: The creation time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.filter description: The FQL filter contained in a rule and used for searching. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.id description: The ID of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.name description: The name for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.permissions description: The permissions of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.priority description: The priority of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status description: The status of a rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.status_message description: The detailed status message. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.topic description: The topic of a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.updated_timestamp description: The last updated time for a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_id description: The user ID of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_name description: The user name of the user that created a given rule. type: String - contextPath: CrowdStrike.domainRulesEntitiesResponseV1.resources.user_uuid description: The UUID of the user that created a given rule. type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatesensorupdatepoliciesv1_resources required: true description: Update Sensor Update Policies by specifying the ID of the policy and details to update. name: cs-update-sensor-update-policies outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV1.resources.platform_name description: The name of the platform. type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatesensorupdatepoliciesv2_resources required: true description: Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection. name: cs-update-sensor-update-policiesv2 outputs: - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesSensorUpdatePoliciesV2.resources.platform_name description: The name of the platform. type: String - arguments: - description: '' name: requests_svexclusionupdatereqv1_comment - description: '' isArray: true name: requests_svexclusionupdatereqv1_groups - description: '' name: requests_svexclusionupdatereqv1_id required: true - description: '' name: requests_svexclusionupdatereqv1_value description: Update the sensor visibility exclusions. name: cs-update-sensor-visibility-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value_hash description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesSvExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: ID of a user. Find a user's ID from `/users/entities/user/v1`. name: user_uuid required: true - description: '' name: domain_updateuserfields_firstname - description: '' name: domain_updateuserfields_lastname description: Modify an existing user's first or last name. name: cs-update-user outputs: - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.customer description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.firstName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.lastName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uuid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.customer description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.firstName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.lastName description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uid description: '' type: String - contextPath: CrowdStrike.domainUserMetaDataResponse.resources.uuid description: '' type: String - arguments: - description: '' isArray: true name: domain_usergroupsrequestv1_resources required: true description: Update existing User Group(s). User Group ID is expected for each User Group definition provided in request body. User Group member(s) remain unaffected. name: cs-update-user-groups outputs: - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.user_group_id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainUserGroupsResponseV1.resources.user_group_id description: '' type: String - arguments: - description: AWS Account ID. isArray: true name: ids required: true - description: Default Region for Account Automation. name: region description: Updates the AWS account per the query meters provided. name: cs-updateaws-account outputs: - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.msaBaseEntitiesResponse.errors.message description: '' type: String - arguments: - description: '' isArray: true name: models_updateawsaccountsv1_resources required: true description: Update AWS Accounts by specifying the ID of the account and details to update. name: cs-updateaws-accounts outputs: - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.alias description: Alias/Name associated with the account. This is only updated once the account is in a registered state. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cid description: '' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_stack_id description: Unique identifier for the cloudformation stack id used for provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudformation_url description: URL of the CloudFormation template to execute. This is returned when mode is to set 'cloudformation' when provisioning. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_owner_id description: The 12 digit AWS account which is hosting the S3 bucket containing cloudtrail logs for this account. If this field is set, it takes precedence of the settings level field. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.cloudtrail_bucket_region description: Region where the S3 bucket containing cloudtrail logs resides. This is only set if using cloudformation to provision and create the trail. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.created_timestamp description: Timestamp of when the account was first provisioned within CrowdStrike's system.' type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.external_id description: ID assigned for use with cross account IAM role access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.iam_role_arn description: The full arn of the IAM role created in this account to control access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.id description: 12 digit AWS provided unique identifier for the account. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_modified_timestamp description: Timestamp of when the account was last modified. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.last_scanned_timestamp description: Timestamp of when the account was scanned. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.policy_version description: Current version of permissions associated with IAM role and granted access. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.provisioning_state description: Provisioning state of the account. Values can be; initiated, registered, unregistered. type: String - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_reqs description: Rate limiting setting to control the maximum number of requests that can be made within the rate_limit_time duration. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.rate_limit_time description: Rate limiting setting to control the number of seconds for which rate_limit_reqs applies. type: Number - contextPath: CrowdStrike.modelsAWSAccountsV1.resources.template_version description: Current version of cloudformation template used to manage access. type: String - arguments: - description: '' isArray: true name: domain_cidgroupsrequestv1_resources required: true description: Update existing CID Group(s). CID Group ID is expected for each CID Group definition provided in request body. CID Group member(s) remain unaffected. name: cs-updatecid-groups outputs: - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.cid_group_id description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.description description: '' type: String - contextPath: CrowdStrike.domainCIDGroupsResponseV1.resources.name description: '' type: String - arguments: - description: Tenant ID to update client ID for. Required if multiple tenants are registered. name: tenant_id - description: Default Subscription ID to patch for all subscriptions belonged to a tenant. name: subscription_id required: true description: Update an Azure default subscription_id in our system for given tenant_id. name: cs-updatecspm-azure-tenant-default-subscriptionid - arguments: - description: '' isArray: true name: registration_policyrequestextv1_resources required: true description: Updates a policy setting - can be used to override policy severity or to disable a policy entirely. name: cs-updatecspm-policy-settings outputs: - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.account_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.enabled description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tag_excluded description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tenant_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_timestamp description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_type description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cid description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cis_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.cloud_service_subtype description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.default_severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.nist_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.benchmark_short description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.pci_benchmark.recommendation_number description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_id description: '' type: Number - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.account_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.enabled description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.severity description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tag_excluded description: '' type: Boolean - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_settings.tenant_id description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_timestamp description: '' type: String - contextPath: CrowdStrike.registrationPolicySettingsResponseV1.resources.policy_type description: '' type: String - arguments: - description: '' isArray: true name: registration_scanscheduleupdaterequestv1_resources required: true description: Updates scan schedule configuration for one or more cloud platforms. name: cs-updatecspm-scan-schedule outputs: - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.cloud_platform description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.next_scan_timestamp description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.scan_schedule description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.cloud_platform description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.next_scan_timestamp description: '' type: String - contextPath: CrowdStrike.registrationScanScheduleResponseV1.resources.scan_schedule description: '' type: String - arguments: - description: '' name: requests_ioaexclusionupdatereqv1_cl_regex required: true - description: '' name: requests_ioaexclusionupdatereqv1_comment - description: '' name: requests_ioaexclusionupdatereqv1_description required: true - description: '' name: requests_ioaexclusionupdatereqv1_detection_json required: true - description: '' isArray: true name: requests_ioaexclusionupdatereqv1_groups required: true - description: '' name: requests_ioaexclusionupdatereqv1_id required: true - description: '' name: requests_ioaexclusionupdatereqv1_ifn_regex required: true - description: '' name: requests_ioaexclusionupdatereqv1_name required: true - description: '' name: requests_ioaexclusionupdatereqv1_pattern_id required: true - description: '' name: requests_ioaexclusionupdatereqv1_pattern_name required: true description: Update the IOA exclusions. name: cs-updateioa-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.cl_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.detection_json description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.ifn_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.cl_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.description description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.detection_json description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.ifn_regex description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.name description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.responsesIoaExclusionRespV1.resources.pattern_name description: '' type: String - arguments: - description: '' name: api_iocviewrecord_batch_id - description: '' name: api_iocviewrecord_created_by - description: '' name: api_iocviewrecord_created_timestamp - description: '' name: api_iocviewrecord_description - description: '' name: api_iocviewrecord_expiration_days - description: '' name: api_iocviewrecord_expiration_timestamp - description: '' name: api_iocviewrecord_modified_by - description: '' name: api_iocviewrecord_modified_timestamp - description: '' name: api_iocviewrecord_policy - description: '' name: api_iocviewrecord_share_level - description: '' name: api_iocviewrecord_source - description: '' name: api_iocviewrecord_type - description: '' name: api_iocviewrecord_value - description: ' The type of the indicator. Valid types include: sha256: A hex-encoded sha256 hash string. Length - min: 64, max: 64. md5: A hex-encoded md5 hash string. Length - min 32, max: 32. domain: A domain name. Length - min: 1, max: 200. ipv4: An IPv4 address. Must be a valid IP address. ipv6: An IPv6 address. Must be a valid IP address. ' name: type_ required: true - description: The string representation of the indicator. name: value required: true description: ' DEPRECATED Use the new IOC Management endpoint (PATCH /iocs/entities/indicators/v1). Update an IOC by providing a type and value.' name: cs-updateioc outputs: - contextPath: CrowdStrike.apiMsaReplyIOC.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.batch_id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.description description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_days description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.policy description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.share_level description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.source description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.type description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.value description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.code description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.errors.id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.errors.message description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.batch_id description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.created_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.description description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_days description: '' type: Number - contextPath: CrowdStrike.apiMsaReplyIOC.resources.expiration_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.modified_timestamp description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.policy description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.share_level description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.source description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.type description: '' type: String - contextPath: CrowdStrike.apiMsaReplyIOC.resources.value description: '' type: String - arguments: - description: '' name: requests_svexclusionupdatereqv1_comment - description: '' isArray: true name: requests_svexclusionupdatereqv1_groups - description: '' name: requests_svexclusionupdatereqv1_id required: true - description: '' name: requests_svexclusionupdatereqv1_value description: Update the ML exclusions. name: cs-updateml-exclusionsv1 outputs: - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.applied_globally description: '' type: Boolean - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.created_on description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.id description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.last_modified description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.modified_by description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.regexp_value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value description: '' type: String - contextPath: CrowdStrike.responsesMlExclusionRespV1.resources.value_hash description: '' type: String - arguments: - description: The user id. name: X_CS_USERNAME required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_default_inbound required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_default_outbound required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_enforce required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_is_default_policy - description: '' name: fwmgr_api_policycontainerupsertrequestv1_platform_id required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_policy_id required: true - description: '' isArray: true name: fwmgr_api_policycontainerupsertrequestv1_rule_group_ids required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_test_mode required: true - description: '' name: fwmgr_api_policycontainerupsertrequestv1_tracking description: Update an identified policy container. name: cs-updatepolicycontainer outputs: - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrmsaReplyMetaOnly.errors.message description: '' type: String - arguments: - description: A collection of policies to update. isArray: true name: requests_updatertresponsepoliciesv1_resources required: true description: Update Response Policies by specifying the ID of the policy and details to update. name: cs-updatert-response-policies outputs: - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.code description: '' type: Number - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.id description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.errors.message description: '' type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.description description: The description of a policy. Use this field to provide a high level summary of what this policy enforces. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.enabled description: If a policy is enabled it will be used during the course of policy evaluation. type: Boolean - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.assignment_rule description: The assignment rule of a group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_by description: The email of the user which created the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.created_timestamp description: The time at which the policy was created. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.description description: An additional description of the group or the devices it targets. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.group_type description: The method by which this host group is managed. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.id description: The identifier of this host group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.groups.name description: The name of the group. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.id description: The unique id of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_by description: The email of the user which last modified the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.modified_timestamp description: The time at which the policy was last modified. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.name description: The human readable name of the policy. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.platform_name description: The name of the platform. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.name description: The name of the category. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.description description: The human readable description of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.id description: The id of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.name description: The name of the setting. type: String - contextPath: CrowdStrike.responsesRTResponsePoliciesV1.resources.settings.settings.type description: The type of the setting which can be used as a hint when displaying in the UI. type: String - arguments: - description: The user id. name: X_CS_USERNAME required: true - description: Audit log comment for this action. name: comment - description: '' isArray: true name: fwmgr_api_rulegroupmodifyrequestv1_diff_operations required: true - description: '' name: fwmgr_api_rulegroupmodifyrequestv1_diff_type required: true - description: '' name: fwmgr_api_rulegroupmodifyrequestv1_id required: true - description: '' isArray: true name: fwmgr_api_rulegroupmodifyrequestv1_rule_ids required: true - description: '' isArray: true name: fwmgr_api_rulegroupmodifyrequestv1_rule_versions required: true - description: '' name: fwmgr_api_rulegroupmodifyrequestv1_tracking required: true description: Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules. name: cs-updaterulegroup outputs: - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.id description: '' type: String - contextPath: CrowdStrike.fwmgrapiQueryResponse.errors.message description: '' type: String - arguments: - description: '' name: api_rulegroupmodifyrequestv1_comment required: true - description: '' name: api_rulegroupmodifyrequestv1_description required: true - description: '' name: api_rulegroupmodifyrequestv1_enabled required: true - description: '' name: api_rulegroupmodifyrequestv1_id required: true - description: '' name: api_rulegroupmodifyrequestv1_name required: true - description: '' name: api_rulegroupmodifyrequestv1_rulegroup_version required: true description: 'Update a rule group. The following properties can be modified: name, description, enabled.' name: cs-updaterulegroup-mixin0 outputs: - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.action_label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.platform description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.action_label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.comment description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.committed_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.created_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.customer_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.description description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_by description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.modified_on description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.rules.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRuleGroupsResponse.resources.version description: '' type: Number - arguments: - description: '' name: api_ruleupdatesrequestv1_comment required: true - description: '' isArray: true name: api_ruleupdatesrequestv1_rule_updates required: true - description: '' name: api_ruleupdatesrequestv1_rulegroup_id required: true - description: '' name: api_ruleupdatesrequestv1_rulegroup_version required: true description: Update rules within a rule group. Return the updated rules. name: cs-updaterules outputs: - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.code description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.errors.id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.errors.message description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.action_label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.comment description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.committed_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.created_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.customer_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.deleted description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.description description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.disposition_id description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.enabled description: '' type: Boolean - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.final_value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.type description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.label description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.field_values.values.value description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.instance_version description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.magic_cookie description: '' type: Number - contextPath: CrowdStrike.apiRulesResponse.resources.modified_by description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.modified_on description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.name description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.pattern_severity description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.rulegroup_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_id description: '' type: String - contextPath: CrowdStrike.apiRulesResponse.resources.ruletype_name description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: 'Content of the uploaded sample in binary format. For example, use `--data-binary @$FILE_PATH` when using cURL. Max file size: 100 MB. Accepted file formats: - Portable executables: `.exe`, `.scr`, `.pif`, `.dll`, `.com`, `.cpl`, etc. - Office documents: `.doc`, `.docx`, `.ppt`, `.pps`, `.pptx`, `.ppsx`, `.xls`, `.xlsx`, `.rtf`, `.pub` - PDF - APK - Executable JAR - Windows script component: `.sct` - Windows shortcut: `.lnk` - Windows help: `.chm` - HTML application: `.hta` - Windows script file: `.wsf` - Javascript: `.js` - Visual Basic: `.vbs`, `.vbe` - Shockwave Flash: `.swf` - Perl: `.pl` - Powershell: `.ps1`, `.psd1`, `.psm1` - Scalable vector graphics: `.svg` - Python: `.py` - Linux ELF executables - Email files: MIME RFC 822 `.eml`, Outlook `.msg`.' isArray: true name: body required: true - description: The binary file. name: upfile required: true - description: Name of the file. name: file_name required: true - description: A descriptive comment to identify the file for other users. name: comment - description: 'Defines visibility of this file in Falcon MalQuery, either via the API or the Falcon console. - `true`: File is only shown to users within your customer account - `false`: File can be seen by other CrowdStrike customers Default: `true`.' name: is_confidential description: Upload a file for sandbox analysis. After uploading, use `/falconx/entities/submissions/v1` to start analyzing the file. name: cs-upload-samplev2 outputs: - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.file_name description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.sha256 description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.file_name description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.sha256 description: '' type: String - arguments: - description: User UUID. name: X_CS_USERUUID - description: 'Content of the uploaded sample in binary format. For example, use `--data-binary @$FILE_PATH` when using cURL. Max file size: 100 MB. Accepted file formats: - Portable executables: `.exe`, `.scr`, `.pif`, `.dll`, `.com`, `.cpl`, etc. - Office documents: `.doc`, `.docx`, `.ppt`, `.pps`, `.pptx`, `.ppsx`, `.xls`, `.xlsx`, `.rtf`, `.pub` - PDF - APK - Executable JAR - Windows script component: `.sct` - Windows shortcut: `.lnk` - Windows help: `.chm` - HTML application: `.hta` - Windows script file: `.wsf` - Javascript: `.js` - Visual Basic: `.vbs`, `.vbe` - Shockwave Flash: `.swf` - Perl: `.pl` - Powershell: `.ps1`, `.psd1`, `.psm1` - Scalable vector graphics: `.svg` - Python: `.py` - Linux ELF executables - Email files: MIME RFC 822 `.eml`, Outlook `.msg`.' isArray: true name: body required: true - description: The binary file. name: upfile required: true - description: Name of the file. name: file_name required: true - description: A descriptive comment to identify the file for other users. name: comment - description: 'Defines visibility of this file in Falcon MalQuery, either via the API or the Falcon console. - `true`: File is only shown to users within your customer account - `false`: File can be seen by other CrowdStrike customers Default: `true`.' name: is_confidential description: Upload a file for further cloud analysis. After uploading, call the specific analysis API endpoint. name: cs-upload-samplev3 outputs: - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.file_name description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.sha256 description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.code description: '' type: Number - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.id description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.errors.message description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.file_name description: '' type: String - contextPath: CrowdStrike.samplestoreSampleMetadataResponseV2.resources.sha256 description: '' type: String - arguments: - description: '' isArray: true name: api_validationrequestv1_fields required: true description: Validates field values and checks for matches if a test string is provided. name: cs-validate outputs: - contextPath: CrowdStrike.apiValidationResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiValidationResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.bytes description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.error description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.matches_test description: '' type: Boolean - contextPath: CrowdStrike.apiValidationResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.test_data description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.valid description: '' type: Boolean - contextPath: CrowdStrike.apiValidationResponseV1.resources.value description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.apiValidationResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.bytes description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.error description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.matches_test description: '' type: Boolean - contextPath: CrowdStrike.apiValidationResponseV1.resources.name description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.test_data description: '' type: String - contextPath: CrowdStrike.apiValidationResponseV1.resources.valid description: '' type: Boolean - contextPath: CrowdStrike.apiValidationResponseV1.resources.value description: '' type: String - arguments: - description: IDs of accounts to verify access on. isArray: true name: ids required: true description: Performs an Access Verification check on the specified AWS Account IDs. name: cs-verifyaws-account-access outputs: - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.reason description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.successful description: '' type: Boolean - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.code description: '' type: Number - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.id description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.errors.message description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.id description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.reason description: '' type: String - contextPath: CrowdStrike.modelsVerifyAccessResponseV1.resources.successful description: '' type: Boolean - arguments: - description: IDs of devices to get the login history for. name: ids required: true description: Retrieve details about recent login sessions for a set of devices. name: cs-get-device-login-history outputs: - contextPath: CrowdStrike.deviceHistoryLogin.errors.code description: '' type: Number - contextPath: CrowdStrike.deviceHistoryLogin.errors.id description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.errors.message description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.resources.device_id description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.resources.recent_logins.login_time description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.resources.recent_logins.user_name description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.meta.powered_by description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.meta.trace_id description: '' type: String - contextPath: CrowdStrike.deviceHistoryLogin.meta.query_time description: '' type: Number - contextPath: CrowdStrike.deviceHistoryLogin.meta.writes description: '' type: Unknown - arguments: - description: IDs of devices to get the network adres history for. name: ids required: true description: Retrieve history of IP and MAC addresses of devices. name: cs-get-device-network-history outputs: - contextPath: CrowdStrike.deviceNetworkHistory.error.code description: '' type: Number - contextPath: CrowdStrike.deviceNetworkHistory.errors.id description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.errors.message description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.meta.powered_by description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.meta.trace_id description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.meta.query_time description: '' type: Number - contextPath: CrowdStrike.deviceNetworkHistory.meta.writes description: '' type: Unknown - contextPath: CrowdStrike.deviceNetworkHistory.resources.device_id description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.resources.cid description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.resources.history.ip_address description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.resources.history.mac_address description: '' type: String - contextPath: CrowdStrike.deviceNetworkHistory.resources.history.timestamp description: '' type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python beta: true fromversion: 6.0.0 tests: - CrowdStrike OpenAPI - Test