Skip to main content
Tools Reference

CrowdStrike Falcon Tools

Written By Christopher Scaminaci

Last updated 7 days ago

CrowdStrike Falcon Tools

falcon_ · 1409 tools · Free 845 · Pro 564Endpoint detection and response across seven families: hosts and policies, detections and intelligence, exposure assessment, Real Time Response and automation, cloud security, containers, and platform administration. The credential is an API client id and secret with a 30-minute token. The cloud region is part of the credential and is never guessed: CrowdStrike serves five regional hosts and publishes no discovery endpoint, so a token minted against the wrong one fails exactly like a wrong secret. API clients carry read and write scopes per service collection, fixed when the client is created, so a 403 means a missing scope rather than a bad key. Every response is the Falcon envelope of meta, resources and errors, and that errors array can be populated on an HTTP 200 when part of a batch fails. Filters use CrowdStrike's own query language. There is no single page-size cap - each endpoint carries its own - and offset paging stops at a 10,000-record window.

All connector tools · CrowdStrike Falcon setup guide

CrowdStrike Falcon tool groups

Certificate Based Exclusions

ToolPlanAccessSummary
falcon_cb_exclusions_create_v1ProDestructiveCreate new Certificate Based Exclusions.
falcon_cb_exclusions_delete_v1ProDestructiveDelete the exclusions by id.
falcon_cb_exclusions_get_v1FreeRead-onlyFind all exclusion IDs matching the query with filter.
falcon_cb_exclusions_query_v1FreeRead-onlySearch for cert-based exclusions.
falcon_cb_exclusions_update_v1ProDestructiveUpdates existing Certificate Based Exclusions.
falcon_certificates_get_v1FreeRead-onlyRetrieves certificate signing information for a file.

[CrowdStrike Falcon] Create new Certificate Based Exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the exclusions by id. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Find all exclusion IDs matching the query with filter. Discover IDs with falcon_cb_exclusions_query_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for cert-based exclusions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_cb_exclusions_get_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Updates existing Certificate Based Exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieves certificate signing information for a file. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

Content Update Policies

ToolPlanAccessSummary
falcon_create_content_update_policiesProWriteCreate Content Update Policies by specifying details about the policy to create.
falcon_delete_content_update_policiesProDestructiveDelete a set of Content Update Policies by specifying their IDs.
falcon_get_content_update_policiesFreeRead-onlyRetrieve a set of Content Update Policies by specifying their IDs.
falcon_perform_content_update_policies_actionProDestructivePerform the specified action on the Content Update Policies specified in the request.
falcon_query_combined_content_update_policiesFreeRead-onlySearch for Content Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_content_update_policy_membersFreeRead-onlySearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_content_update_policiesFreeRead-onlySearch for Content Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_content_update_policy_membersFreeRead-onlySearch for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_pinnable_content_versionsFreeRead-onlySearch for content versions available for pinning given the category.
falcon_set_content_update_policies_precedenceProDestructiveSets the precedence of Content Update Policies based on the order of IDs specified in the request.
falcon_update_content_update_policiesProDestructiveUpdate Content Update Policies by specifying the ID of the policy and details to update.

[CrowdStrike Falcon] Create Content Update Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Content Update Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Content Update Policies by specifying their IDs. Discover IDs with falcon_query_content_update_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Perform the specified action on the Content Update Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Content Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Content Update Policy IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_content_update_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for content versions available for pinning given the category. This returns matching IDs only, not the records themselves. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
categorystringyesRequired. Value for the Falcon category parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Sets the precedence of Content Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Content Update Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Deployments

ToolPlanAccessSummary
falcon_combined_release_notes_v1FreeRead-onlyQueries for release-notes resources and returns details.
falcon_combined_releases_v1_mixin0FreeRead-onlyQueries for releases resources and returns details.
falcon_get_deployments_external_v1FreeRead-onlyGet deployment resources by ids.
falcon_get_entity_i_ds_by_query_postFreeRead-onlyreturns the release notes for the IDs in the request.
falcon_get_entity_i_ds_by_query_postv2FreeRead-onlyreturns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format.
falcon_query_release_notes_v1FreeRead-onlyQueries for release-notes resources and returns ids.

[CrowdStrike Falcon] Queries for release-notes resources and returns details. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Queries for releases resources and returns details. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get deployment resources by ids. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] returns the release notes for the IDs in the request. Discover IDs with falcon_query_release_notes_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format. Discover IDs with falcon_query_release_notes_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Queries for release-notes resources and returns ids. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_entity_i_ds_by_query_post to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Device Content

ToolPlanAccessSummary
falcon_entities_states_v1FreeRead-onlyRetrieve the host content state for a number of ids between 1 and 100. Discover IDs with falcon_queries_states_v1. Returns the raw Falcon envelope: meta, resources and errors.
falcon_queries_states_v1FreeRead-onlyQuery for the content state of the host.

[CrowdStrike Falcon] Retrieve the host content state for a number of ids between 1 and 100. Discover IDs with falcon_queries_states_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Query for the content state of the host. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_states_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Device Control Policies

ToolPlanAccessSummary
falcon_create_device_control_policiesProWriteCreate Device Control Policies by specifying details about the policy to create.
falcon_delete_device_control_policiesProDestructiveDelete a set of Device Control Policies by specifying their IDs.
falcon_get_default_device_control_policiesFreeRead-onlyRetrieve the configuration for a Default Device Control Policy.
falcon_get_default_device_control_settingsFreeRead-onlyGet default device control settings (USB and Bluetooth).
falcon_get_device_control_policiesFreeRead-onlyRetrieve a set of Device Control Policies by specifying their IDs.
falcon_get_device_control_policies_v2FreeRead-onlyGet device control policies for the given filter criteria.
falcon_patch_device_control_policies_classes_v1ProDestructiveWeakens or changes which USB and Bluetooth device classes this policy blocks, for every host in its scope.
falcon_patch_device_control_policies_v2ProDestructiveWeakens or changes USB and Bluetooth enforcement for every host in this device control policy's scope.
falcon_perform_device_control_policies_actionProDestructivePerform the specified action on the Device Control Policies specified in the request.
falcon_post_device_control_policies_v2ProWriteCreate/clone a device control policy (USB and Bluetooth).
falcon_query_combined_device_control_policiesFreeRead-onlySearch for Device Control Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_device_control_policy_membersFreeRead-onlySearch for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
falcon_query_device_control_policiesFreeRead-onlySearch for Device Control Policies in your environment by providing an FQL filter and paging details.
falcon_query_device_control_policy_membersFreeRead-onlySearch for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
falcon_set_device_control_policies_precedenceProDestructiveSets the precedence of Device Control Policies based on the order of IDs specified in the request.
falcon_update_default_device_control_policiesProDestructiveUpdate the configuration for a Default Device Control Policy.
falcon_update_default_device_control_settingsProDestructiveUpdate the configuration for Default Device Control Settings.
falcon_update_device_control_policiesProDestructiveUpdate Device Control Policies by specifying the ID of the policy and details to update.

[CrowdStrike Falcon] Create Device Control Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Device Control Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve the configuration for a Default Device Control Policy. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Get default device control settings (USB and Bluetooth). Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Retrieve a set of Device Control Policies by specifying their IDs. Discover IDs with falcon_query_device_control_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get device control policies for the given filter criteria. (USB and Bluetooth). Discover IDs with falcon_query_device_control_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Weakens or changes which USB and Bluetooth device classes this policy blocks, for every host in its scope. Opening a class removes the block that was stopping those devices from being used. This is a partial merge, so classes you omit keep their current settings. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Weakens or changes USB and Bluetooth enforcement for every host in this device control policy's scope. Updates the policy's base settings; this is a partial merge, so settings you omit keep their current values. The v1 twin of this tool is falcon_update_device_control_policies. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Perform the specified action on the Device Control Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create/clone a device control policy (USB and Bluetooth). Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Device Control Policies in your environment by providing an FQL filter and paging details. Returns a set of Device Control Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Device Control Policies in your environment by providing an FQL filter and paging details. Returns a set of Device Control Policy IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_device_control_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Sets the precedence of Device Control Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update the configuration for a Default Device Control Policy. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update the configuration for Default Device Control Settings. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Device Control Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Firewall Management

ToolPlanAccessSummary
falcon_aggregate_eventsFreeRead-onlyAggregate events for customer.
falcon_aggregate_policy_rulesFreeRead-onlyAggregate rules within a policy for customer.
falcon_aggregate_rule_groupsFreeRead-onlyAggregate rule groups for customer.
falcon_aggregate_rulesFreeRead-onlyAggregate rules for customer.
falcon_create_network_locationsProWriteCreate new network locations provided, and return the ID.
falcon_create_rule_groupProWriteCreate new rule group on a platform for a customer with a name and description, and return the ID.
falcon_create_rule_group_validationProWriteValidates the request of creating a new rule group on a platform for a customer with a name and description.
falcon_delete_network_locationsProDestructiveDelete network location entities by ID.
falcon_firewall_delete_rule_groupsProDestructiveDelete rule group entities by ID.
falcon_firewall_get_rule_groupsFreeRead-onlyGet rule group entities by ID.
falcon_firewall_get_rulesFreeRead-onlyGet rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string).
falcon_firewall_query_eventsFreeRead-onlyFind all event IDs matching the query with filter.
falcon_firewall_query_rule_groupsFreeRead-onlyFind all rule group IDs matching the query with filter.
falcon_firewall_query_rulesFreeRead-onlyFind all rule IDs matching the query with filter.
falcon_get_eventsFreeRead-onlyGet events entities by ID and optionally version.
falcon_get_firewall_fieldsFreeRead-onlyGet the firewall field specifications by ID.
falcon_get_network_locationsFreeRead-onlyGet a summary of network locations entities by ID.
falcon_get_network_locations_detailsFreeRead-onlyGet network locations entities by ID.
falcon_get_platformsFreeRead-onlyGet platforms by ID, e.g., windows or mac or droid.
falcon_get_policy_containersFreeRead-onlyGet policy container entities by policy ID.
falcon_query_firewall_fieldsFreeRead-onlyGet the firewall field specification IDs for the provided platform.
falcon_query_network_locationsFreeRead-onlyGet a list of network location IDs.
falcon_query_platformsFreeRead-onlyGet the list of platform names.
falcon_query_policy_rulesFreeRead-onlyFind all firewall rule IDs matching the query with filter, and return them in precedence order.
falcon_update_network_locationsProWriteUpdates the network locations provided, and return the ID.
falcon_update_network_locations_metadataProWriteUpdates the network locations metadata such as polling_intervals for the cid.
falcon_update_network_locations_precedenceProDestructiveUpdates the network locations precedence according to the list of ids provided.
falcon_update_policy_containerProDestructiveUpdate an identified policy container, including local logging functionality.
falcon_update_rule_groupProDestructiveUpdate name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules.
falcon_update_rule_group_validationProWriteValidates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules.
falcon_upsert_network_locationsProDestructiveUpdates the network locations provided, and return the ID.
falcon_validate_filepath_patternProWriteValidates that the test pattern matches the executable filepath glob pattern.

[CrowdStrike Falcon] Aggregate events for customer. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Aggregate rules within a policy for customer. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Aggregate rule groups for customer. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Aggregate rules for customer. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create new network locations provided, and return the ID. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
addFwRulesbooleannonullOptional. True or false for the Falcon add_fw_rules parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
cloneIdstringnonullOptional. Value for the Falcon clone_id parameter.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Create new rule group on a platform for a customer with a name and description, and return the ID. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
cloneIdstringnonullOptional. Value for the Falcon clone_id parameter.
commentstringnonullOptional audit comment recorded against this change in Falcon.
librarystringnonullOptional. Value for the Falcon library parameter.

[CrowdStrike Falcon] Validates the request of creating a new rule group on a platform for a customer with a name and description. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
cloneIdstringnonullOptional. Value for the Falcon clone_id parameter.
commentstringnonullOptional audit comment recorded against this change in Falcon.
librarystringnonullOptional. Value for the Falcon library parameter.

[CrowdStrike Falcon] Delete network location entities by ID. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete rule group entities by ID. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get rule group entities by ID. These groups do not contain their rule entites, just the rule IDs in precedence order. Discover IDs with falcon_firewall_query_rule_groups. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string). Discover IDs with falcon_firewall_query_rules. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Find all event IDs matching the query with filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_events to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Find all rule group IDs matching the query with filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_firewall_get_rule_groups to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Find all rule IDs matching the query with filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_firewall_get_rules to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get events entities by ID and optionally version. Discover IDs with falcon_firewall_query_events. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the firewall field specifications by ID. Discover IDs with falcon_query_firewall_fields. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get a summary of network locations entities by ID. Discover IDs with falcon_query_network_locations. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get network locations entities by ID. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get platforms by ID, e.g., windows or mac or droid. Discover IDs with falcon_query_platforms. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get policy container entities by policy ID. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the firewall field specification IDs for the provided platform. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_firewall_fields to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
platformIdstringnonullOptional. Value for the Falcon platform_id parameter.

[CrowdStrike Falcon] Get a list of network location IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_network_locations to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get the list of platform names. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_platforms to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Find all firewall rule IDs matching the query with filter, and return them in precedence order. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Updates the network locations provided, and return the ID. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Updates the network locations metadata such as polling_intervals for the cid. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Updates the network locations precedence according to the list of ids provided. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Update an identified policy container, including local logging functionality. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Updates the network locations provided, and return the ID. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.

[CrowdStrike Falcon] Validates that the test pattern matches the executable filepath glob pattern. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Firewall Policies

ToolPlanAccessSummary
falcon_create_firewall_policiesProWriteCreate Firewall Policies by specifying details about the policy to create.
falcon_delete_firewall_policiesProDestructiveDelete a set of Firewall Policies by specifying their IDs.
falcon_get_firewall_policiesFreeRead-onlyRetrieve a set of Firewall Policies by specifying their IDs.
falcon_perform_firewall_policies_actionProDestructivePerform the specified action on the Firewall Policies specified in the request.
falcon_query_combined_firewall_policiesFreeRead-onlySearch for Firewall Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_firewall_policy_membersFreeRead-onlySearch for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
falcon_query_firewall_policiesFreeRead-onlySearch for Firewall Policies in your environment by providing an FQL filter and paging details.
falcon_query_firewall_policy_membersFreeRead-onlySearch for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
falcon_set_firewall_policies_precedenceProDestructiveSets the precedence of Firewall Policies based on the order of IDs specified in the request.
falcon_update_firewall_policiesProDestructiveUpdate Firewall Policies by specifying the ID of the policy and details to update.

[CrowdStrike Falcon] Create Firewall Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
cloneIdstringnonullOptional. Value for the Falcon clone_id parameter.

[CrowdStrike Falcon] Delete a set of Firewall Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Firewall Policies by specifying their IDs. Discover IDs with falcon_query_firewall_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Perform the specified action on the Firewall Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Firewall Policies in your environment by providing an FQL filter and paging details. Returns a set of Firewall Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Firewall Policies in your environment by providing an FQL filter and paging details. Returns a set of Firewall Policy IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_firewall_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Sets the precedence of Firewall Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Firewall Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Host Groups

ToolPlanAccessSummary
falcon_create_host_groupsProWriteCreate Host Groups by specifying details about the group to create.
falcon_delete_host_groupsProDestructiveDelete a set of Host Groups by specifying their IDs.
falcon_get_host_groupsFreeRead-onlyRetrieve a set of Host Groups by specifying their IDs.
falcon_perform_group_actionProDestructivePerform the specified action on the Host Groups specified in the request.
falcon_query_combined_group_membersFreeRead-onlySearch for members of a Host Group in your environment by providing an FQL filter and paging details.
falcon_query_combined_host_groupsFreeRead-onlySearch for Host Groups in your environment by providing an FQL filter and paging details.
falcon_query_group_membersFreeRead-onlySearch for members of a Host Group in your environment by providing an FQL filter and paging details.
falcon_query_host_groupsFreeRead-onlySearch for Host Groups in your environment by providing an FQL filter and paging details.
falcon_update_host_groupsProDestructiveEdits a host group in place.

[CrowdStrike Falcon] Create Host Groups by specifying details about the group to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Host Groups by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Host Groups by specifying their IDs. Discover IDs with falcon_query_host_groups. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Perform the specified action on the Host Groups specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
disableHostnameCheckbooleannonullOptional. True or false for the Falcon disable_hostname_check parameter.

[CrowdStrike Falcon] Search for members of a Host Group in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Host Groups in your environment by providing an FQL filter and paging details. Returns a set of Host Groups which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Host Group in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Host Groups in your environment by providing an FQL filter and paging details. Returns a set of Host Group IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_host_groups to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Edits a host group in place. Host group membership drives policy assignment, so a change here can move hosts out of the policy scope that was protecting them. Creating a new group with falcon_create_host_groups is additive and is not gated this way. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Host Migration

ToolPlanAccessSummary
falcon_create_migration_v1ProDestructiveCreate a device migration job.
falcon_get_host_migration_i_ds_v1FreeRead-onlyQuery host migration IDs.
falcon_get_host_migrations_v1FreeRead-onlyGet host migration details.
falcon_get_migration_destinations_v1FreeRead-onlyGet destinations for a migration.
falcon_get_migration_i_ds_v1FreeRead-onlyQuery migration jobs.
falcon_get_migrations_v1FreeRead-onlyGet migration job details.
falcon_host_migration_aggregates_v1FreeRead-onlyGet host migration aggregates as specified via json in request body.
falcon_host_migrations_actions_v1ProDestructivePerform an action on host migrations.
falcon_migration_aggregates_v1FreeRead-onlyGet migration aggregates as specified via json in request body.
falcon_migrations_actions_v1ProDestructivePerform an action on a migration job.

[CrowdStrike Falcon] Create a device migration job. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Query host migration IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_host_migrations_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringyesRequired. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get host migration details. Discover IDs with falcon_get_host_migration_i_ds_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get destinations for a migration. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Query migration jobs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_migrations_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get migration job details. Discover IDs with falcon_get_migration_i_ds_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get host migration aggregates as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Perform an action on host migrations. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get migration aggregates as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Perform an action on a migration job. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

Hosts

ToolPlanAccessSummary
falcon_combined_devices_by_filterFreeRead-onlySearch for hosts in your environment by platform, hostname, IP, and other criteria.
falcon_combined_hidden_devices_by_filterFreeRead-onlySearch for hidden hosts in your environment by platform, hostname, IP, and other criteria.
falcon_devices_actions_delete_v1ProDestructivePermanently delete hosts from the system.
falcon_entities_perform_actionProDestructivePerforms the specified action on the provided group IDs.
falcon_get_device_detailsFreeRead-onlyGet details on one or more hosts by providing host IDs in a POST body.
falcon_get_device_details_v1FreeRead-onlyGet details on one or more hosts by providing agent IDs (AID).
falcon_get_device_details_v2FreeRead-onlyGet details on one or more hosts by providing host IDs as a query parameter.
falcon_get_online_state_v1FreeRead-onlyGet the online status for one or more hosts by specifying each host’s unique ID.
falcon_perform_action_v2ProDestructiveTake various actions on the hosts in your environment.
falcon_post_device_details_v2FreeRead-onlyGet details on one or more hosts by providing host IDs in a POST body.
falcon_query_device_login_historyFreeRead-onlyRetrieve details about recent login sessions for a set of devices.
falcon_query_device_login_history_v2FreeRead-onlyRetrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.
falcon_query_devices_by_filterFreeRead-onlySearch for hosts in your environment by platform, hostname, IP, and other criteria.
falcon_query_devices_by_filter_scrollFreeRead-onlySearch for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit).
falcon_query_get_network_address_history_v1FreeRead-onlyRetrieve history of IP and MAC addresses of devices.
falcon_query_hidden_devicesFreeRead-onlyRetrieve hidden hosts that match the provided filter criteria.
falcon_update_device_tagsProDestructiveAppend or remove one or more Falcon Grouping Tags on one or more hosts.

[CrowdStrike Falcon] Search for hosts in your environment by platform, hostname, IP, and other criteria. Returns full device records. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. Value for the Falcon fields parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for hidden hosts in your environment by platform, hostname, IP, and other criteria. Returns full device records. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. Value for the Falcon fields parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Permanently delete hosts from the system. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Performs the specified action on the provided group IDs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
disableHostnameCheckbooleannonullOptional. True or false for the Falcon disable_hostname_check parameter.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get details on one or more hosts by providing host IDs in a POST body. Supports up to a maximum 5000 IDs. Discover IDs with falcon_query_devices_by_filter. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get details on one or more hosts by providing agent IDs (AID). You can get a host's agent IDs (AIDs) from the QueryDevicesByFilter endpoint, the Falcon console or the Streaming API. Discover IDs with falcon_query_devices_by_filter. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get details on one or more hosts by providing host IDs as a query parameter. Supports up to a maximum 100 IDs. Discover IDs with falcon_query_devices_by_filter. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the online status for one or more hosts by specifying each host’s unique ID. Successful requests return an HTTP 200 response and the status for each host identified by a `state` of `online`, `offline`, or `unknown` for each host, identified by host `id`. QueryDevicesByFilter to get a list of host IDs. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Take various actions on the hosts in your environment. Contain or lift containment on a host. Hide or unhide a host. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get details on one or more hosts by providing host IDs in a POST body. Supports up to a maximum 5000 IDs. Discover IDs with falcon_query_devices_by_filter. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve details about recent login sessions for a set of devices. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline. A max of 10 device ids can be specified. Use limit to bound the response size. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
fromstringnonullOptional. Value for the Falcon from parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
tostringnonullOptional. Value for the Falcon to parameter.

[CrowdStrike Falcon] Search for hosts in your environment by platform, hostname, IP, and other criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_device_details to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit). This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Retrieve history of IP and MAC addresses of devices. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve hidden hosts that match the provided filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Append or remove one or more Falcon Grouping Tags on one or more hosts. Tags must be of the form FalconGroupingTags/. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Installation Tokens

ToolPlanAccessSummary
falcon_audit_events_queryFreeRead-onlySearch for audit events by providing an FQL filter and paging details.
falcon_audit_events_readFreeRead-onlyGets the details of one or more audit events by id.
falcon_customer_settings_readFreeRead-onlyCheck current installation token settings.
falcon_customer_settings_updateProDestructiveUpdate installation token settings.
falcon_tokens_createProDestructiveCreates a token.
falcon_tokens_deleteProDestructiveDeletes a token immediately.
falcon_tokens_queryFreeRead-onlySearch for tokens by providing an FQL filter and paging details.
falcon_tokens_readFreeRead-onlyGets the details of one or more tokens by id.
falcon_tokens_updateProDestructiveUpdates one or more tokens.

[CrowdStrike Falcon] Search for audit events by providing an FQL filter and paging details. This returns matching IDs only, not the records themselves — pass the IDs to falcon_audit_events_read to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 1000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Gets the details of one or more audit events by id. Discover IDs with falcon_audit_events_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Check current installation token settings. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Update installation token settings. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Creates a token. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Deletes a token immediately. To revoke a token, use tokens_update instead. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for tokens by providing an FQL filter and paging details. This returns matching IDs only, not the records themselves — pass the IDs to falcon_tokens_read to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 1000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Gets the details of one or more tokens by id. Discover IDs with falcon_tokens_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Updates one or more tokens. Use this endpoint to edit labels, change expiration, revoke, or restore. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idsstringyesOne or more record IDs, comma-separated.

IOA Exclusions

ToolPlanAccessSummary
falcon_create_ioa_exclusions_v1ProDestructiveCreate the IOA exclusions.
falcon_delete_ioa_exclusions_v1ProDestructiveDelete the IOA exclusions by id.
falcon_get_ioa_exclusions_v1FreeRead-onlyGet a set of IOA Exclusions by specifying their IDs.
falcon_query_ioa_exclusions_v1FreeRead-onlySearch for IOA exclusions.
falcon_ss_ioa_exclusions_aggregates_v2FreeRead-onlyGet Self Service IOA Exclusion aggregates as specified via json in the request body.
falcon_ss_ioa_exclusions_create_v2ProDestructiveCreate new Self Service IOA Exclusions.
falcon_ss_ioa_exclusions_delete_v2ProDestructiveDelete the Self Service IOA Exclusions rule by id.
falcon_ss_ioa_exclusions_get_reports_v2ProDestructiveCreate a report of Self Service IOA Exclusions scoped by the given filters.
falcon_ss_ioa_exclusions_get_v2FreeRead-onlyGet the Self Service IOA Exclusions rules by id.
falcon_ss_ioa_exclusions_matched_rule_v2FreeRead-onlyGet Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent.
falcon_ss_ioa_exclusions_new_rules_v2FreeRead-onlyGet defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
falcon_ss_ioa_exclusions_search_v2FreeRead-onlySearch for Self Service IOA Exclusions.
falcon_ss_ioa_exclusions_update_v2ProDestructiveUpdate the Self Service IOA Exclusions rule by id.
falcon_update_ioa_exclusions_v1ProDestructiveUpdate the IOA exclusions.

[CrowdStrike Falcon] Create the IOA exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the IOA exclusions by id. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get a set of IOA Exclusions by specifying their IDs. Discover IDs with falcon_query_ioa_exclusions_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for IOA exclusions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_ioa_exclusions_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
clRegexstringnonullOptional. Value for the Falcon cl_regex parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
ifnRegexstringnonullOptional. Value for the Falcon ifn_regex parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get Self Service IOA Exclusion aggregates as specified via json in the request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
clRegexstringnonullOptional. Value for the Falcon cl_regex parameter.
grandparentClRegexstringnonullOptional. Value for the Falcon grandparent_cl_regex parameter.
grandparentIfnRegexstringnonullOptional. Value for the Falcon grandparent_ifn_regex parameter.
ifnRegexstringnonullOptional. Value for the Falcon ifn_regex parameter.
parentClRegexstringnonullOptional. Value for the Falcon parent_cl_regex parameter.
parentIfnRegexstringnonullOptional. Value for the Falcon parent_ifn_regex parameter.

[CrowdStrike Falcon] Create new Self Service IOA Exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the Self Service IOA Exclusions rule by id. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a report of Self Service IOA Exclusions scoped by the given filters. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get the Self Service IOA Exclusions rules by id. Discover IDs with falcon_ss_ioa_exclusions_search_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Self Service IOA Exclusions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_ss_ioa_exclusions_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
clRegexstringnonullOptional. Value for the Falcon cl_regex parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
grandparentClRegexstringnonullOptional. Value for the Falcon grandparent_cl_regex parameter.
grandparentIfnRegexstringnonullOptional. Value for the Falcon grandparent_ifn_regex parameter.
ifnRegexstringnonullOptional. Value for the Falcon ifn_regex parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
parentClRegexstringnonullOptional. Value for the Falcon parent_cl_regex parameter.
parentIfnRegexstringnonullOptional. Value for the Falcon parent_ifn_regex parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update the Self Service IOA Exclusions rule by id. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update the IOA exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

ML Exclusions

ToolPlanAccessSummary
falcon_create_ml_exclusions_v1ProDestructiveCreate the ML exclusions.
falcon_delete_ml_exclusions_v1ProDestructiveDelete the ML exclusions by id.
falcon_exclusions_aggregates_v2FreeRead-onlyGet exclusion aggregates as specified via json in request body.
falcon_exclusions_create_v2ProDestructiveCreate the exclusions, with ancestor fields.
falcon_exclusions_delete_v2ProDestructiveDelete the exclusions by id, with ancestor fields.
falcon_exclusions_get_all_v2FreeRead-onlyGet all exclusions.
falcon_exclusions_get_reports_v2ProDestructiveCreate a report of ML exclusions scoped by the given filters.
falcon_exclusions_get_v2FreeRead-onlyGet the exclusions by id, with ancestor fields.
falcon_exclusions_perform_action_v2ProDestructiveActions used to manipulate the content of exclusions, with ancestor fields.
falcon_exclusions_sdmf_query_v1ProDestructiveExecutes an SDMF data frame query against exclusion entities.
falcon_exclusions_search_v2FreeRead-onlySearch for exclusions, with ancestor fields.
falcon_exclusions_update_v2ProDestructiveUpdate the exclusions by id, with ancestor fields.
falcon_get_ml_exclusions_v1FreeRead-onlyGet a set of ML Exclusions by specifying their IDs.
falcon_query_ml_exclusions_v1FreeRead-onlySearch for ML exclusions.
falcon_update_ml_exclusions_v1ProDestructiveUpdate the ML exclusions.

[CrowdStrike Falcon] Create the ML exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the ML exclusions by id. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get exclusion aggregates as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create the exclusions, with ancestor fields. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the exclusions by id, with ancestor fields. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get all exclusions. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Create a report of ML exclusions scoped by the given filters. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get the exclusions by id, with ancestor fields. Discover IDs with falcon_exclusions_search_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Actions used to manipulate the content of exclusions, with ancestor fields. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Executes an SDMF data frame query against exclusion entities. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for exclusions, with ancestor fields. This returns matching IDs only, not the records themselves — pass the IDs to falcon_exclusions_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update the exclusions by id, with ancestor fields. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get a set of ML Exclusions by specifying their IDs. Discover IDs with falcon_query_ml_exclusions_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for ML exclusions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_ml_exclusions_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update the ML exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Mobile Enrollment

ToolPlanAccessSummary
falcon_request_device_enrollment_v3ProWriteTrigger on-boarding process for a mobile device.
falcon_request_device_enrollment_v4ProWriteTrigger on-boarding process for a mobile device.

[CrowdStrike Falcon] Trigger on-boarding process for a mobile device. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringnonullOptional. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.

[CrowdStrike Falcon] Trigger on-boarding process for a mobile device. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringnonullOptional. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.

Prevention Policies

ToolPlanAccessSummary
falcon_create_prevention_policiesProWriteCreate Prevention Policies by specifying details about the policy to create.
falcon_delete_prevention_policiesProDestructiveDelete a set of Prevention Policies by specifying their IDs.
falcon_get_prevention_policiesFreeRead-onlyRetrieve a set of Prevention Policies by specifying their IDs.
falcon_perform_prevention_policies_actionProDestructivePerform the specified action on the Prevention Policies specified in the request.
falcon_query_combined_prevention_policiesFreeRead-onlySearch for Prevention Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_prevention_policy_membersFreeRead-onlySearch for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
falcon_query_prevention_policiesFreeRead-onlySearch for Prevention Policies in your environment by providing an FQL filter and paging details.
falcon_query_prevention_policy_membersFreeRead-onlySearch for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
falcon_set_prevention_policies_precedenceProDestructiveSets the precedence of Prevention Policies based on the order of IDs specified in the request.
falcon_update_prevention_policiesProDestructiveUpdate Prevention Policies by specifying the ID of the policy and details to update.

[CrowdStrike Falcon] Create Prevention Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Prevention Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Prevention Policies by specifying their IDs. Discover IDs with falcon_query_prevention_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Perform the specified action on the Prevention Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Prevention Policies in your environment by providing an FQL filter and paging details. Returns a set of Prevention Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Prevention Policies in your environment by providing an FQL filter and paging details. Returns a set of Prevention Policy IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_prevention_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Sets the precedence of Prevention Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Prevention Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Profile Groups

ToolPlanAccessSummary
falcon_create_group_v1_mixin0ProWriteCreate a new profile group.
falcon_delete_groups_v1ProDestructiveDelete profile groups by IDs.
falcon_get_group_users_v1FreeRead-onlyGet a list of groups with users that belong to them.
falcon_get_groups_v1_mixin0FreeRead-onlyGet profile groups by IDs with full details.
falcon_get_user_groups_v1FreeRead-onlyGet a list of users with the groups that they belong to.
falcon_group_actions_v1_mixin0ProDestructivePerform actions on profile groups (add/remove roles, user groups, FGA objects).
falcon_group_users_actions_v1_mixin0ProDestructiveAdd or remove users from profile groups.
falcon_query_groups_v1_mixin0FreeRead-onlyQuery profile group IDs with FQL filtering, pagination, and sorting.
falcon_update_group_v1_mixin0ProWriteUpdate profile group metadata (name, description).

[CrowdStrike Falcon] Create a new profile group. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete profile groups by IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get a list of groups with users that belong to them. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get profile groups by IDs with full details. Discover IDs with falcon_query_groups_v1_mixin0. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get a list of users with the groups that they belong to. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Perform actions on profile groups (add/remove roles, user groups, FGA objects). Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Add or remove users from profile groups. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Query profile group IDs with FQL filtering, pagination, and sorting. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_groups_v1_mixin0 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update profile group metadata (name, description). Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

Response Policies

ToolPlanAccessSummary
falcon_create_rt_response_policiesProWriteCreate Response Policies by specifying details about the policy to create.
falcon_delete_rt_response_policiesProDestructiveDelete a set of Response Policies by specifying their IDs.
falcon_get_rt_response_policiesFreeRead-onlyRetrieve a set of Response Policies by specifying their IDs.
falcon_perform_rt_response_policies_actionProDestructivePerform the specified action on the Response Policies specified in the request.
falcon_query_combined_rt_response_policiesFreeRead-onlySearch for Response Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_rt_response_policy_membersFreeRead-onlySearch for members of a Response policy in your environment by providing an FQL filter and paging details.
falcon_query_rt_response_policiesFreeRead-onlySearch for Response Policies in your environment by providing an FQL filter with sort and/or paging details.
falcon_query_rt_response_policy_membersFreeRead-onlySearch for members of a Response policy in your environment by providing an FQL filter and paging details.
falcon_set_rt_response_policies_precedenceProDestructiveSets the precedence of Response Policies based on the order of IDs specified in the request.
falcon_update_rt_response_policiesProDestructiveUpdate Response Policies by specifying the ID of the policy and details to update.

[CrowdStrike Falcon] Create Response Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Response Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Response Policies by specifying their IDs. Discover IDs with falcon_query_rt_response_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Perform the specified action on the Response Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Response Policies in your environment by providing an FQL filter and paging details. Returns a set of Response Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Response policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details. This returns a set of Response Policy IDs that match the given criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rt_response_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Response policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Sets the precedence of Response Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Response Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Sensor Download

ToolPlanAccessSummary
falcon_get_sensor_installers_by_queryFreeRead-onlyGet sensor installer IDs by provided query.
falcon_get_sensor_installers_by_query_v2FreeRead-onlyGet sensor installer IDs by provided query.
falcon_get_sensor_installers_by_query_v3FreeRead-onlyGet sensor installer IDs by provided query.
falcon_get_sensor_installers_ccid_by_queryFreeRead-onlyGet CCID to use with sensor installers.
falcon_get_sensor_installers_entitiesFreeRead-onlyGet sensor installer details by provided SHA256 IDs.
falcon_get_sensor_installers_entities_v2FreeRead-onlyGet sensor installer details by provided SHA256 IDs.
falcon_get_sensor_installers_entities_v3FreeRead-onlyGet sensor installer details by provided SHA256 IDs.

[CrowdStrike Falcon] Get sensor installer IDs by provided query. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_installers_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get sensor installer IDs by provided query. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_installers_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get sensor installer IDs by provided query. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_installers_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get CCID to use with sensor installers. This returns matching IDs only, not the records themselves. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Get sensor installer details by provided SHA256 IDs. Discover IDs with falcon_get_sensor_installers_by_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get sensor installer details by provided SHA256 IDs. Discover IDs with falcon_get_sensor_installers_by_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get sensor installer details by provided SHA256 IDs. Discover IDs with falcon_get_sensor_installers_by_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

Sensor Update Policy

ToolPlanAccessSummary
falcon_create_sensor_update_policiesProWriteCreate Sensor Update Policies by specifying details about the policy to create.
falcon_create_sensor_update_policies_v2ProWriteCreate Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection.
falcon_delete_sensor_update_policiesProDestructiveDelete a set of Sensor Update Policies by specifying their IDs.
falcon_get_sensor_update_policiesFreeRead-onlyRetrieve a set of Sensor Update Policies by specifying their IDs.
falcon_get_sensor_update_policies_v2FreeRead-onlyRetrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs.
falcon_increment_uninstall_tokenProDestructiveIncrements a bulk maintenance token.
falcon_perform_sensor_update_policies_actionProDestructivePerform the specified action on the Sensor Update Policies specified in the request.
falcon_query_combined_sensor_update_buildsFreeRead-onlyRetrieve available builds for use with Sensor Update Policies.
falcon_query_combined_sensor_update_kernelsFreeRead-onlyRetrieve kernel compatibility info for Sensor Update Builds.
falcon_query_combined_sensor_update_policiesFreeRead-onlySearch for Sensor Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_sensor_update_policies_v2FreeRead-onlySearch for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details.
falcon_query_combined_sensor_update_policy_membersFreeRead-onlySearch for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_sensor_update_kernels_distinctFreeRead-onlyRetrieve kernel compatibility info for Sensor Update Builds.
falcon_query_sensor_update_policiesFreeRead-onlySearch for Sensor Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_sensor_update_policy_membersFreeRead-onlySearch for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
falcon_reveal_uninstall_tokenProWriteReveals an uninstall token for a specific device.
falcon_set_sensor_update_policies_precedenceProDestructiveSets the precedence of Sensor Update Policies based on the order of IDs specified in the request.
falcon_update_sensor_update_policiesProDestructiveUpdate Sensor Update Policies by specifying the ID of the policy and details to update.
falcon_update_sensor_update_policies_v2ProDestructiveUpdate Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection.

[CrowdStrike Falcon] Create Sensor Update Policies by specifying details about the policy to create. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete a set of Sensor Update Policies by specifying their IDs. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Sensor Update Policies by specifying their IDs. Discover IDs with falcon_query_sensor_update_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs. Discover IDs with falcon_query_sensor_update_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Increments a bulk maintenance token. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Perform the specified action on the Sensor Update Policies specified in the request. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionNamestringyesRequired. Value for the Falcon action_name parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve available builds for use with Sensor Update Policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
platformstringnonullOptional. Value for the Falcon platform parameter.
stagestringnonullOptional. One or more values, comma-separated for the Falcon stage parameter.

[CrowdStrike Falcon] Retrieve kernel compatibility info for Sensor Update Builds. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policies which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. Returns a set of host details which match the filter criteria. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Retrieve kernel compatibility info for Sensor Update Builds. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
distinctFieldstringyesThe distinct-field path value.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. Returns a set of Sensor Update Policy IDs which match the filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_update_policies to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. Returns a set of Agent IDs which match the filter criteria. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idstringnonullOptional. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Reveals an uninstall token for a specific device. To retrieve the bulk maintenance token pass the value 'MAINTENANCE' as the value for 'device_id'. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request. The first ID specified will have the highest precedence and the last ID specified will have the lowest. You must specify all non-Default Policies for a platform when updating precedence. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Sensor Update Policies by specifying the ID of the policy and details to update. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Sensor Usage

ToolPlanAccessSummary
falcon_get_sensor_usage_hourlyFreeRead-onlyFetches hourly average.
falcon_get_sensor_usage_weeklyFreeRead-onlyFetches weekly average.

[CrowdStrike Falcon] Fetches hourly average. Each data point represents the average of how many unique AIDs were seen per hour for the previous 28 days. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.

[CrowdStrike Falcon] Fetches weekly average. Each data point represents the average of how many unique AIDs were seen per week for the previous 28 days. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.

Sensor Visibility Exclusions

ToolPlanAccessSummary
falcon_create_sv_exclusions_v1ProDestructiveCreate the sensor visibility exclusions.
falcon_delete_sensor_visibility_exclusions_v1ProDestructiveDelete the sensor visibility exclusions by id.
falcon_get_sensor_visibility_exclusions_v1FreeRead-onlyGet a set of Sensor Visibility Exclusions by specifying their IDs.
falcon_query_sensor_visibility_exclusions_v1FreeRead-onlySearch for sensor visibility exclusions.
falcon_update_sensor_visibility_exclusions_v1ProDestructiveUpdate the sensor visibility exclusions.

[CrowdStrike Falcon] Create the sensor visibility exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete the sensor visibility exclusions by id. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get a set of Sensor Visibility Exclusions by specifying their IDs. Discover IDs with falcon_query_sensor_visibility_exclusions_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for sensor visibility exclusions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_visibility_exclusions_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update the sensor visibility exclusions. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Alerts

ToolPlanAccessSummary
falcon_get_queries_alerts_v2FreeRead-onlySearch for alert IDs matching an FQL filter.
falcon_patch_entities_alerts_v1ProDestructiveApply an action to one or more detections by detection ID.
falcon_patch_entities_alerts_v3ProDestructiveApply an action to one or more alerts by composite ID.
falcon_post_aggregates_alerts_v2FreeRead-onlyRetrieves aggregate values for Alerts across all CIDs.
falcon_post_combined_alerts_v1FreeRead-onlySearch alerts with an FQL filter and get the full records back in one call.
falcon_post_entities_alerts_v2FreeRead-onlyRead full alert records for the composite IDs you supply.

[CrowdStrike Falcon] Search for alert IDs matching an FQL filter. The alerts collection replaces the retired detects and incidents APIs, so this is the entry point for detection triage. This returns matching IDs only, not the records themselves — pass the IDs to falcon_post_entities_alerts_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
includeHiddenbooleannonullOptional. True or false for the Falcon include_hidden parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Apply an action to one or more detections by detection ID. The action name is carried in the request body: update_status, assign_to_user_id, assign_to_uuid, assign_to_name, unassign, add_tag, remove_tag, remove_tags_by_prefix, append_comment, show_in_ui and new_behavior_processed. Updating the status closes or reopens the detection for every analyst in the Falcon console, and show_in_ui set to false hides it from the alerts list, so confirm the action name and the ID list before you send it. This is the older detection-ID surface; prefer falcon_patch_entities_alerts_v3, which takes composite IDs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Apply an action to one or more alerts by composite ID. The action name is carried in the request body: update_status, assign, unassign, add_tag, remove_tag, remove_tags_by_prefix, append_comment and show_in_ui. Updating the status closes or reopens the alert for every analyst in the Falcon console, and show_in_ui set to false hides it from the alerts list. When one request both adds and removes tags, Falcon removes before it adds. The alerts collection replaces the retired detects and incidents APIs, so this is the surface for all detection triage. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
includeHiddenbooleannonullOptional. True or false for the Falcon include_hidden parameter.

[CrowdStrike Falcon] Retrieves aggregate values for Alerts across all CIDs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
includeHiddenbooleannonullOptional. True or false for the Falcon include_hidden parameter.

[CrowdStrike Falcon] Search alerts with an FQL filter and get the full records back in one call. This is the surface for large result sets, above about 10,000 alerts, because it pages on an after token instead of an offset. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read full alert records for the composite IDs you supply. Discover the IDs with falcon_get_queries_alerts_v2, or use falcon_post_combined_alerts_v1 to search and read in one call. Discover IDs with falcon_get_queries_alerts_v2. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
includeHiddenbooleannonullOptional. True or false for the Falcon include_hidden parameter.

Hunting

ToolPlanAccessSummary
falcon_aggregate_hunting_guidesFreeRead-onlyAggregate Hunting Guides.
falcon_aggregate_intelligence_queriesFreeRead-onlyAggregate intelligence queries.
falcon_get_archive_exportFreeRead-onlyCreates an Archive Export.
falcon_get_hunting_guidesFreeRead-onlyRetrieves a list of Hunting Guides.
falcon_get_intelligence_queriesFreeRead-onlyRetrieves the details of a list of Intelligence queries IDs.
falcon_search_hunting_guidesFreeRead-onlySearch for Hunting Guides that match the provided conditions.
falcon_search_intelligence_queriesFreeRead-onlySearch for a list of intelligence queries IDs that match the provided conditions.

[CrowdStrike Falcon] Aggregate Hunting Guides. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Aggregate intelligence queries. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Creates an Archive Export. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
archiveTypestringnonullOptional. Value for the Falcon archive_type parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
languagestringyesRequired. Value for the Falcon language parameter.

[CrowdStrike Falcon] Retrieves a list of Hunting Guides. Discover IDs with falcon_search_hunting_guides. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieves the details of a list of Intelligence queries IDs. Discover IDs with falcon_search_intelligence_queries. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
includeTranslatedContentstringnonullOptional. One or more values, comma-separated for the Falcon include_translated_content parameter.

[CrowdStrike Falcon] Search for Hunting Guides that match the provided conditions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_hunting_guides to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for a list of intelligence queries IDs that match the provided conditions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_intelligence_queries to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

Correlation Rules

ToolPlanAccessSummary
falcon_aggregates_rule_versions_post_v1FreeRead-onlyGet rules aggregates as specified via json in the request body.
falcon_combined_rules_get_v1FreeRead-onlySearch correlation rules with a query and filter and get the full records back in one call, instead of searching for IDs and reading them separately.
falcon_combined_rules_get_v2FreeRead-onlyFind all rules matching the query and filter.
falcon_entities_latest_rules_get_v1FreeRead-onlyRetrieve latest rule versions by rule IDs.
falcon_entities_rule_versions_delete_v1ProDestructiveDelete correlation rule versions by ID.
falcon_entities_rule_versions_export_post_v1ProWriteExport correlation rule versions.
falcon_entities_rule_versions_import_post_v1ProDestructiveImport correlation rule versions from an exported payload.
falcon_entities_rule_versions_publish_patch_v1ProDestructivePublish an existing correlation rule version.
falcon_entities_rules_delete_v1ProDestructiveDelete correlation rules by ID.
falcon_entities_rules_get_v1FreeRead-onlyRead full correlation rule records for the IDs you supply.
falcon_entities_rules_get_v2FreeRead-onlyRetrieve rule versions by IDs.
falcon_entities_rules_patch_v1ProDestructiveUpdate existing correlation rules.
falcon_entities_rules_post_v1ProWriteCreate a correlation rule.
falcon_entities_templates_get_v1_mixin0FreeRead-onlyRetrieve rule templates by IDs.
falcon_entities_templates_rules_post_v1ProWriteCreate a correlation rule from a CrowdStrike rule template.
falcon_queries_rules_get_v1FreeRead-onlySearch for correlation rule IDs matching a query and filter.
falcon_queries_rules_get_v2FreeRead-onlyFind all rule version IDs matching the query and filter.
falcon_queries_templates_get_v1_mixin0FreeRead-onlySearch rule template IDs matching the filter.

[CrowdStrike Falcon] Get rules aggregates as specified via json in the request body. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search correlation rules with a query and filter and get the full records back in one call, instead of searching for IDs and reading them separately. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Find all rules matching the query and filter. Supported filters: customer_id,user_id,user_uuid,status,name,created_on,last_updated_on Supported range filters: created_on,last_updated_on. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Retrieve latest rule versions by rule IDs. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
ruleIdsstringyesRequired. One or more values, comma-separated for the Falcon rule_ids parameter.

[CrowdStrike Falcon] Delete correlation rule versions by ID. The version and its history are removed, so a rule published from it can no longer be reproduced. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Export correlation rule versions. This reads rule content Falcon already holds and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Import correlation rule versions from an exported payload. This is a bulk write: one call can create rules and overwrite existing ones, so review the payload before you send it. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Publish an existing correlation rule version. Publishing makes that version the live one, so it replaces the logic the rule was running and changes detection behavior across the whole customer estate immediately. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete correlation rules by ID. Deleting a rule stops every detection it was generating, and neither the rule nor its versions can be recovered through the API. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read full correlation rule records for the IDs you supply. Discover IDs with falcon_queries_rules_get_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve rule versions by IDs. Discover IDs with falcon_queries_rules_get_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update existing correlation rules. A correlation rule is live detection logic, so an edit changes what Next-Gen SIEM detects across the whole customer estate from the moment it is saved. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a correlation rule. A new rule is added to Next-Gen SIEM and no existing rule is changed. Its logic goes live when a version is published with falcon_entities_rule_versions_publish_patch_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve rule templates by IDs. Discover IDs with falcon_queries_templates_get_v1_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a correlation rule from a CrowdStrike rule template. A new rule is added and no existing rule is changed. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for correlation rule IDs matching a query and filter. Supported filter fields include customer_id, user_id, user_name, name, description, status, severity and created_on. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_rules_get_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Find all rule version IDs matching the query and filter. Supported filters: customer_id,user_id,user_uui d,status,name,created_on,last_updated_on,state,version,rule_id,executor_rule_id Supported range filters: created_on,last_updated_on. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_rules_get_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search rule template IDs matching the filter. Supported filters: name,description,vendor,outcome,mitre_attack.tactic_id,mitre_attack.technique_id,type Supported range filters: created_on,last_updated_on. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_templates_get_v1_mixin0 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Correlation Rules Admin

ToolPlanAccessSummary
falcon_entities_rules_ownership_put_v1ProDestructiveChange the owner of an existing correlation rule.
falcon_entities_rules_ownership_put_v2ProDestructiveBulk change the owner of existing correlation rules.

[CrowdStrike Falcon] Change the owner of an existing correlation rule. The previous owner loses their ownership rights over the rule. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Bulk change the owner of existing correlation rules. Every previous owner in the list loses their ownership rights, in one call. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Custom Indicators of Attack

ToolPlanAccessSummary
falcon_create_ruleProDestructiveCreate a rule inside a Custom IOA rule group and return it.
falcon_create_rule_group_mixin0ProWriteCreate a Custom IOA rule group for a platform, with a name and an optional description, and return it.
falcon_delete_rule_groups_mixin0ProDestructiveDelete Custom IOA rule groups by ID.
falcon_get_patternsFreeRead-onlyGet pattern severities by ID.
falcon_get_platforms_mixin0FreeRead-onlyGet platforms by ID.
falcon_get_rule_groups_mixin0FreeRead-onlyRead full Custom IOA rule groups by ID, including the rules they contain.
falcon_get_rule_typesFreeRead-onlyGet rule types by ID.
falcon_get_rules_getFreeRead-onlyGet rules by ID and optionally with cid and/or version in the following format: `[cid:]ID[:version]`.
falcon_get_rules_mixin0FreeRead-onlyRead full Custom IOA rules by ID, optionally with a customer ID and a version, in the form [cid:]ID[:version].
falcon_ioa_delete_rulesProDestructiveDelete rules from a Custom IOA rule group by ID.
falcon_ioa_update_rulesProDestructiveUpdate rules inside a Custom IOA rule group and return them.
falcon_query_patternsFreeRead-onlyGet all pattern severity IDs.
falcon_query_platforms_mixin0FreeRead-onlyGet all platform IDs.
falcon_query_rule_groups_fullFreeRead-onlyFind all rule groups matching the query with optional filter.
falcon_query_rule_groups_mixin0FreeRead-onlySearch for Custom IOA rule group IDs matching a query, with an optional filter.
falcon_query_rule_typesFreeRead-onlyGet all rule type IDs.
falcon_query_rules_mixin0FreeRead-onlySearch for Custom IOA rule IDs matching a query, with an optional filter.
falcon_update_rule_group_mixin0ProDestructiveUpdate a Custom IOA rule group.
falcon_update_rules_v2ProDestructiveUpdate the name, description, enabled flag or field values of individual rules in a Custom IOA rule group and return them.
falcon_validateProWriteValidate Custom IOA rule field values and, when a test string is supplied, report whether it matches.

[CrowdStrike Falcon] Create a rule inside a Custom IOA rule group and return it. A Custom IOA rule is live detection and prevention content: once its rule group is enabled and attached to a prevention policy, the rule acts on every host that policy covers. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a Custom IOA rule group for a platform, with a name and an optional description, and return it. The group holds no rules and acts on no host until rules are added to it and it is attached to a prevention policy. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Custom IOA rule groups by ID. Every rule in the group goes with it, and any prevention policy that used the group loses that detection coverage. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get pattern severities by ID. Discover IDs with falcon_query_patterns. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get platforms by ID. Discover IDs with falcon_query_platforms_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read full Custom IOA rule groups by ID, including the rules they contain. Discover IDs with falcon_query_rule_groups_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get rule types by ID. Discover IDs with falcon_query_rule_types. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get rules by ID and optionally with cid and/or version in the following format: `[cid:]ID[:version]`. Discover IDs with falcon_query_rules_mixin0. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read full Custom IOA rules by ID, optionally with a customer ID and a version, in the form [cid:]ID[:version]. Discover IDs with falcon_query_rules_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete rules from a Custom IOA rule group by ID. The hosts covered by the group lose the detection or prevention those rules provided. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
idsstringyesOne or more record IDs, comma-separated.
ruleGroupIdstringyesRequired. Value for the Falcon rule_group_id parameter.

[CrowdStrike Falcon] Update rules inside a Custom IOA rule group and return them. CrowdStrike documents this v1 call as requiring the complete state of every rule in the group, so any rule missing from the payload is replaced rather than left alone. Use falcon_update_rules_v2 to change a subset safely. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get all pattern severity IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_patterns to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Get all platform IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_platforms_mixin0 to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Find all rule groups matching the query with optional filter. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for Custom IOA rule group IDs matching a query, with an optional filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rule_groups_mixin0 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get all rule type IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rule_types to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Search for Custom IOA rule IDs matching a query, with an optional filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rules_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update a Custom IOA rule group. The name, description and enabled flag can be changed. Turning the enabled flag off silences every rule in the group at once, on every host the policy covers. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update the name, description, enabled flag or field values of individual rules in a Custom IOA rule group and return them. Unlike the v1 call this accepts a subset of the group, but it still changes live detection and prevention content: disabling a rule removes the coverage it was giving every host under the policy. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Validate Custom IOA rule field values and, when a test string is supplied, report whether it matches. Nothing is saved and no host is affected. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Falcon Identity

ToolPlanAccessSummary
falcon_delete_third_party_passkey_registryProDestructiveDelete third party passkey registries.
falcon_get_third_party_passkey_registryFreeRead-onlyFetches third party passkey registries.
falcon_query_third_party_passkey_registryFreeRead-onlyQuery third party passkey registries.
falcon_update_third_party_passkey_registryProDestructiveUpdate third party passkey registries.

[CrowdStrike Falcon] Delete third party passkey registries. Removing a registry withdraws trust from the passkeys it covers, and the users who authenticate with them lose that factor. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Fetches third party passkey registries. Discover IDs with falcon_query_third_party_passkey_registry. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Query third party passkey registries. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_third_party_passkey_registry to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update third party passkey registries. A registry decides which external passkey provider Falcon Identity trusts as an authentication factor, so an edit changes who can sign in and how. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Falcon Sandbox

ToolPlanAccessSummary
falcon_delete_reportProDestructiveDelete a sandbox report by report ID.
falcon_delete_sample_v2ProDestructiveRemove a sample from the collection, including the file, its metadata and its submissions.
falcon_get_memory_dumpFreeRead-onlyRead the content of a sandbox memory dump.
falcon_get_memory_dump_extracted_stringsFreeRead-onlyGet extracted strings from a memory dump.
falcon_get_memory_dump_hex_dumpFreeRead-onlyGet hex view of a memory dump.
falcon_get_reportsFreeRead-onlyRead a full sandbox report by report ID, including the behavioral analysis.
falcon_get_submissionsFreeRead-onlyCheck the status of a sandbox analysis.
falcon_get_summary_reportsFreeRead-onlyRead the short summary form of a sandbox report by report ID.
falcon_query_reportsFreeRead-onlySearch for sandbox report IDs with an FQL filter.
falcon_query_sample_v1FreeRead-onlyRetrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200. This returns matching IDs only, not the records themselves.
falcon_query_submissionsFreeRead-onlyFind submission IDs for uploaded files by providing an FQL filter and paging details.
falcon_submitProDestructiveSubmit an uploaded file or a URL to Falcon Sandbox for analysis.
falcon_upload_sample_v2ProDestructiveUpload a file to Falcon Sandbox for analysis.

[CrowdStrike Falcon] Delete a sandbox report by report ID. Confirm the removal by polling the report summaries endpoint. The analysis result is gone, and only a fresh submission reproduces it. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Remove a sample from the collection, including the file, its metadata and its submissions. Nothing about the sample survives, and any report that referenced it loses its source file. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read the content of a sandbox memory dump. CrowdStrike serves this endpoint as a binary stream rather than JSON, so the call fails with a content type error; read the extracted strings or the hex view instead, or download the dump from the Falcon console. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
namestringnonullOptional. Value for the Falcon name parameter.

[CrowdStrike Falcon] Get extracted strings from a memory dump. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
namestringnonullOptional. Value for the Falcon name parameter.

[CrowdStrike Falcon] Get hex view of a memory dump. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
namestringnonullOptional. Value for the Falcon name parameter.

[CrowdStrike Falcon] Read a full sandbox report by report ID, including the behavioral analysis. Use falcon_get_summary_reports for the short form. Discover IDs with falcon_query_reports. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Check the status of a sandbox analysis. Time required for analysis varies but is usually less than 15 minutes. Discover IDs with falcon_query_submissions. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read the short summary form of a sandbox report by report ID. Use falcon_get_reports for the full behavioral analysis. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search for sandbox report IDs with an FQL filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_reports to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200. This returns matching IDs only, not the records themselves. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Find submission IDs for uploaded files by providing an FQL filter and paging details. Returns a set of submission IDs that match your criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_submissions to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Submit an uploaded file or a URL to Falcon Sandbox for analysis. This detonates the sample in CrowdStrike cloud, and a URL submission means CrowdStrike fetches that URL. Analysis time varies and is usually under 15 minutes; poll falcon_get_submissions for the status. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
aidstringnonullOptional. Value for the Falcon aid parameter.
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Upload a file to Falcon Sandbox for analysis. The file leaves the customer environment for CrowdStrike cloud and is retained there, which cannot be undone through the API, so confirm the customer is willing to share the artifact before you send it. After uploading, start the analysis with falcon_submit. Supply the file as base64 in fileContentBase64 together with its uploadFileName. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
fileContentBase64stringyesThe file content, base64-encoded.
fileNamestringyesRequired. Value for the Falcon file_name parameter.
isConfidentialbooleannonullOptional. True or false for the Falcon is_confidential parameter.
uploadFileNamestringyesThe file name to upload.

Identity Protection

ToolPlanAccessSummary
falcon_delete_policy_rulesProDestructiveDelete Identity Protection policy rules.
falcon_get_policy_rulesFreeRead-onlyGet policy rules.
falcon_get_policy_rules_queryFreeRead-onlyQuery policy rule IDs.
falcon_get_sensor_aggregatesFreeRead-onlyGet sensor aggregates as specified via json in request body.
falcon_get_sensor_detailsFreeRead-onlyRead details for one or more Identity Protection sensors by device ID, supplied in the request body.
falcon_post_graphqlProDestructiveRun a GraphQL operation against the Identity Protection API.
falcon_post_policy_rulesProDestructiveCreate an Identity Protection policy rule.
falcon_query_sensors_by_filterFreeRead-onlySearch for Identity Protection sensors in the customer environment by hostname, address and other criteria, and return their IDs.

[CrowdStrike Falcon] Delete Identity Protection policy rules. Removing a rule removes the enforcement it applied, so the identity traffic it used to block or challenge is allowed through from that moment. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get policy rules. Discover IDs with falcon_get_policy_rules_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Query policy rule IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_policy_rules to read the detail. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
enabledbooleannonullOptional. True or false for the Falcon enabled parameter.
namestringnonullOptional. Value for the Falcon name parameter.
simulationModebooleannonullOptional. True or false for the Falcon simulation_mode parameter.

[CrowdStrike Falcon] Get sensor aggregates as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read details for one or more Identity Protection sensors by device ID, supplied in the request body. CrowdStrike accepts up to 5,000 IDs per call. Discover the IDs with falcon_query_sensors_by_filter. Discover IDs with falcon_query_sensors_by_filter. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Run a GraphQL operation against the Identity Protection API. The API serves entities, timeline activities, identity-based incidents and security assessment data, and CrowdStrike also exposes actions on entities and incidents through the same endpoint, so the operation text you supply decides whether this reads or writes. Treat it as a write surface and review the operation before you send it. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create an Identity Protection policy rule. A policy rule takes effect on the directory as soon as it is created, so it starts blocking, challenging with multifactor authentication, or permitting identity traffic immediately. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for Identity Protection sensors in the customer environment by hostname, address and other criteria, and return their IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_sensor_details to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 200 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Intel

ToolPlanAccessSummary
falcon_cao_incidents_aggregates_v1FreeRead-onlyPerform statistical aggregations over incident data.
falcon_cao_incidents_entities_v1FreeRead-onlyRetrieve full details for one or more adversary incidents by their IDs.
falcon_cao_incidents_queries_v1FreeRead-onlySearch for adversary incidents using FQL criteria and return a paginated list of matching incident IDs.
falcon_get_intel_actor_entitiesFreeRead-onlyRead full CrowdStrike Intelligence adversary profiles for the actor IDs you supply.
falcon_get_intel_indicator_entitiesFreeRead-onlyRead full CrowdStrike Intelligence indicator records for the indicator IDs you supply.
falcon_get_intel_report_entitiesFreeRead-onlyRead full CrowdStrike Intelligence reports for the report IDs you supply.
falcon_get_intel_report_pdfFreeRead-onlyRead the PDF attachment of a CrowdStrike Intelligence report.
falcon_get_intel_rule_entitiesFreeRead-onlyRetrieve details for rule sets for the specified ids.
falcon_get_intel_rule_fileFreeRead-onlyDownload an earlier CrowdStrike Intelligence rule set.
falcon_get_latest_intel_rule_fileFreeRead-onlyDownload the latest CrowdStrike Intelligence rule set.
falcon_get_malware_entitiesFreeRead-onlyGet malware entities for specified ids.
falcon_get_malware_mitre_reportFreeRead-onlyExport Mitre ATT&CK information for a given malware family.
falcon_get_mitre_reportFreeRead-onlyExport Mitre ATT&CK information for a given actor.
falcon_intel_get_vulnerabilitiesFreeRead-onlyGet vulnerabilities.
falcon_intel_query_vulnerabilitiesFreeRead-onlyGet vulnerabilities IDs.
falcon_post_mitre_attacksFreeRead-onlyRetrieves report and observable IDs associated with the given actor and attacks.
falcon_query_intel_actor_entitiesFreeRead-onlySearch CrowdStrike Intelligence adversaries with an FQL filter and get the full profiles back in one call.
falcon_query_intel_actor_idsFreeRead-onlySearch CrowdStrike Intelligence for adversary IDs matching an FQL filter.
falcon_query_intel_indicator_entitiesFreeRead-onlySearch CrowdStrike Intelligence indicators with an FQL filter and get the full records back in one call.
falcon_query_intel_indicator_idsFreeRead-onlySearch CrowdStrike Intelligence for indicator IDs matching an FQL filter.
falcon_query_intel_report_entitiesFreeRead-onlySearch CrowdStrike Intelligence reports with an FQL filter and get the full records back in one call.
falcon_query_intel_report_idsFreeRead-onlySearch CrowdStrike Intelligence for report IDs matching an FQL filter.
falcon_query_intel_rule_idsFreeRead-onlySearch for rule IDs that match provided filter criteria.
falcon_query_malwareFreeRead-onlyGet malware family names that match provided FQL filters.
falcon_query_malware_entitiesFreeRead-onlyGet malware entities that match provided FQL filters.
falcon_query_mitre_attacksFreeRead-onlyGets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071. This returns matching IDs only, not the records…
falcon_query_mitre_attacks_for_malwareFreeRead-onlyGets MITRE tactics and techniques for the given malware.

[CrowdStrike Falcon] Perform statistical aggregations over incident data. Available aggregation properties: MitreAttack.TechniqueId, ActivityStart, ActivityEnd, Objectives.Slug, TargetCountries.Slug, TargetIndustries.Name, TargetRegions.Slug, MitreAttack.TechniqueName, Id, Motivations.Slug, InvolvesAdversaries.AnimalClassifier, TargetIndustries.Slug, MitreAttack.TacticName, PublishDate, InvolvesAdversaries.Slug, InvolvesThreats.FamilyName, TargetRegions.Name, MitreAttack.TacticId, TargetCountries.Name. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieve full details for one or more adversary incidents by their IDs. Returns complete incident data including adversary activity, timestamps, and associated metadata. Discover IDs with falcon_cao_incidents_queries_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs. Use the returned IDs with the entities endpoint to retrieve full incident details. This returns matching IDs only, not the records themselves — pass the IDs to falcon_cao_incidents_entities_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Read full CrowdStrike Intelligence adversary profiles for the actor IDs you supply. Discover IDs with falcon_query_intel_actor_ids. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. One or more values, comma-separated for the Falcon fields parameter.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read full CrowdStrike Intelligence indicator records for the indicator IDs you supply. Discover IDs with falcon_query_intel_indicator_ids. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read full CrowdStrike Intelligence reports for the report IDs you supply. Discover IDs with falcon_query_intel_report_ids. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. One or more values, comma-separated for the Falcon fields parameter.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read the PDF attachment of a CrowdStrike Intelligence report. CrowdStrike serves this endpoint as a binary stream rather than JSON, so the call fails with a content type error; download the PDF from the Falcon console instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringnonullOptional. Value for the Falcon id parameter.
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve details for rule sets for the specified ids. Discover IDs with falcon_query_intel_rule_ids. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Download an earlier CrowdStrike Intelligence rule set. CrowdStrike serves this endpoint as a file stream rather than JSON, so the call fails with a content type error; download the rule set from the Falcon console instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
formatstringnonullOptional. Value for the Falcon format parameter.
idintegeryesRequired. Numeric value for the Falcon id parameter.

[CrowdStrike Falcon] Download the latest CrowdStrike Intelligence rule set. CrowdStrike serves this endpoint as a file stream rather than JSON, so the call fails with a content type error; download the rule set from the Falcon console instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
formatstringnonullOptional. Value for the Falcon format parameter.
typestringyesRequired. Value for the Falcon type parameter.

[CrowdStrike Falcon] Get malware entities for specified ids. Discover IDs with falcon_query_malware. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Export Mitre ATT&CK information for a given malware family. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
formatstringyesRequired. Value for the Falcon format parameter.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Export Mitre ATT&CK information for a given actor. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actorIdstringyesRequired. Value for the Falcon actor_id parameter.
formatstringyesRequired. Value for the Falcon format parameter.

[CrowdStrike Falcon] Get vulnerabilities. Discover IDs with falcon_intel_query_vulnerabilities. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get vulnerabilities IDs. This returns matching IDs only, not the records themselves — pass the IDs to falcon_intel_get_vulnerabilities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Retrieves report and observable IDs associated with the given actor and attacks. Discover IDs with falcon_query_mitre_attacks. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search CrowdStrike Intelligence adversaries with an FQL filter and get the full profiles back in one call. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. One or more values, comma-separated for the Falcon fields parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search CrowdStrike Intelligence for adversary IDs matching an FQL filter. Adversaries are CrowdStrike named threat actors. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_intel_actor_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search CrowdStrike Intelligence indicators with an FQL filter and get the full records back in one call. These are CrowdStrike published indicators, not the customer own custom indicators of compromise. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
includeDeletedbooleannonullOptional. True or false for the Falcon include_deleted parameter.
includeRelationsbooleannonullOptional. True or false for the Falcon include_relations parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search CrowdStrike Intelligence for indicator IDs matching an FQL filter. These are CrowdStrike published threat intelligence indicators, not the customer own custom indicators of compromise, which live under falcon_indicator_search_v1. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_intel_indicator_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
includeDeletedbooleannonullOptional. True or false for the Falcon include_deleted parameter.
includeRelationsbooleannonullOptional. True or false for the Falcon include_relations parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 10000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search CrowdStrike Intelligence reports with an FQL filter and get the full records back in one call. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. One or more values, comma-separated for the Falcon fields parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search CrowdStrike Intelligence for report IDs matching an FQL filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_intel_report_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for rule IDs that match provided filter criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_intel_rule_entities to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
descriptionstringnonullOptional. One or more values, comma-separated for the Falcon description parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
maxCreatedDatestringnonullOptional. Value for the Falcon max_created_date parameter.
minCreatedDateintegernonullOptional. Numeric value for the Falcon min_created_date parameter.
namestringnonullOptional. One or more values, comma-separated for the Falcon name parameter.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.
tagsstringnonullOptional. One or more values, comma-separated for the Falcon tags parameter.
typestringyesRequired. Value for the Falcon type parameter.

[CrowdStrike Falcon] Get malware family names that match provided FQL filters. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_malware_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get malware entities that match provided FQL filters. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional. One or more values, comma-separated for the Falcon fields parameter.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Gets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071. This returns matching IDs only, not the records themselves — pass the IDs to falcon_post_mitre_attacks to read the detail. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringnonullOptional. Value for the Falcon id parameter.
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Gets MITRE tactics and techniques for the given malware. This returns matching IDs only, not the records themselves. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

Intelligence Feeds

ToolPlanAccessSummary
falcon_list_feed_typesFreeRead-onlyLists the accessible feed types for a given customer.
falcon_query_feed_archivesFreeRead-onlyQueries the accessible feed types for a customer.

[CrowdStrike Falcon] Lists the accessible feed types for a given customer. Discover IDs with falcon_query_feed_archives. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Queries the accessible feed types for a customer. Returns a list of feed item IDs which can be later downloaded. This returns matching IDs only, not the records themselves — pass the IDs to falcon_list_feed_types to read the detail. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
feedIntervalstringnonullOptional. Value for the Falcon feed_interval parameter.
feedNamestringyesRequired. Value for the Falcon feed_name parameter.
sincestringnonullOptional. Value for the Falcon since parameter.

Intelligence Indicator Graph

ToolPlanAccessSummary
falcon_lookup_indicatorsFreeRead-onlyLook up indicator graph records by their value, such as a hash, domain or address, rather than by ID.
falcon_search_indicatorsFreeRead-onlySearch the CrowdStrike indicator graph with an FQL filter.

[CrowdStrike Falcon] Look up indicator graph records by their value, such as a hash, domain or address, rather than by ID. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search the CrowdStrike indicator graph with an FQL filter. The graph relates indicators to the adversaries, malware families and reports that CrowdStrike associates with them. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Indicators of Compromise

ToolPlanAccessSummary
falcon_action_get_v1FreeRead-onlyGet Actions by ids.
falcon_action_query_v1FreeRead-onlyQuery Actions.
falcon_get_indicators_reportFreeRead-onlyLaunch an indicators report creation job.
falcon_indicator_aggregate_v1FreeRead-onlyGet Indicators aggregates as specified via json in the request body.
falcon_indicator_combined_v1FreeRead-onlySearch custom indicators of compromise with an FQL filter and get the full records back in one call, instead of searching for IDs and reading them separately.
falcon_indicator_create_v1ProDestructiveCreate custom indicators of compromise.
falcon_indicator_delete_v1ProDestructiveDelete custom indicators of compromise by ID.
falcon_indicator_get_device_count_v1FreeRead-onlyGet the number of devices the indicator has run on.
falcon_indicator_get_devices_ran_on_v1FreeRead-onlyGet the IDs of devices the indicator has run on.
falcon_indicator_get_processes_ran_on_v1FreeRead-onlyGet the number of processes the indicator has run on.
falcon_indicator_get_v1FreeRead-onlyRead full custom indicator of compromise records for the IDs you supply.
falcon_indicator_sdmf_query_v1ProWriteRun a structured data frame query over custom indicators of compromise.
falcon_indicator_search_v1FreeRead-onlySearch for custom indicator of compromise IDs with an FQL filter.
falcon_indicator_update_v1ProDestructiveUpdate custom indicators of compromise by ID.
falcon_ioc_type_query_v1FreeRead-onlyQuery IOC Types.
falcon_platform_query_v1FreeRead-onlyQuery Platforms.
falcon_severity_query_v1FreeRead-onlyQuery Severities.

[CrowdStrike Falcon] Get Actions by ids. Discover IDs with falcon_action_query_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Query Actions. This returns matching IDs only, not the records themselves — pass the IDs to falcon_action_get_v1 to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Launch an indicators report creation job. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get Indicators aggregates as specified via json in the request body. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
fromParentbooleannonullOptional. True or false for the Falcon from_parent parameter.

[CrowdStrike Falcon] Search custom indicators of compromise with an FQL filter and get the full records back in one call, instead of searching for IDs and reading them separately. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
fromParentbooleannonullOptional. True or false for the Falcon from_parent parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Create custom indicators of compromise. Each indicator carries an action that applies to every host in the customer estate: prevent blocks the file, hash, domain or address, and allow adds it to the allowlist so Falcon stops acting on it. An allow indicator is an exclusion, and it weakens protection everywhere at once. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
ignoreWarningsbooleannonullOptional. True or false for the Falcon ignore_warnings parameter.
retrodetectsbooleannonullOptional. True or false for the Falcon retrodetects parameter.

[CrowdStrike Falcon] Delete custom indicators of compromise by ID. A deleted prevent indicator stops blocking, and a deleted allow indicator puts the item back under normal detection, so protection changes on every host either way. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
fromParentbooleannonullOptional. True or false for the Falcon from_parent parameter.
idsstringnonullOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the number of devices the indicator has run on. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] Get the IDs of devices the indicator has run on. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitstringnonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] Get the number of processes the indicator has run on. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
deviceIdstringyesRequired. Value for the Falcon device_id parameter.
limitstringnonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] Read full custom indicator of compromise records for the IDs you supply. Discover IDs with falcon_indicator_search_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Run a structured data frame query over custom indicators of compromise. This reads indicator data and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for custom indicator of compromise IDs with an FQL filter. These are the customer own indicators; CrowdStrike published threat intelligence indicators live under falcon_query_intel_indicator_ids. This returns matching IDs only, not the records themselves — pass the IDs to falcon_indicator_get_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
fromParentbooleannonullOptional. True or false for the Falcon from_parent parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update custom indicators of compromise by ID. Changing an indicator action changes protection across the whole customer estate: moving it to allow stops Falcon acting on that file, hash, domain or address on every host. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
ignoreWarningsbooleannonullOptional. True or false for the Falcon ignore_warnings parameter.
retrodetectsbooleannonullOptional. True or false for the Falcon retrodetects parameter.

[CrowdStrike Falcon] Query IOC Types. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Query Platforms. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Query Severities. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
ToolPlanAccessSummary
falcon_devices_countFreeRead-onlyNumber of hosts in your customer account that have observed a given custom IOC.
falcon_devices_ran_onFreeRead-onlyFind the hosts that have observed a given custom indicator of compromise, and return their device IDs.
falcon_entities_processesFreeRead-onlyFor the provided ProcessID retrieve the process details.
falcon_processes_ran_onFreeRead-onlyFind the processes associated with a given custom indicator of compromise on a specific host, and return their process IDs.

[CrowdStrike Falcon] Number of hosts in your customer account that have observed a given custom IOC. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] Find the hosts that have observed a given custom indicator of compromise, and return their device IDs. Read the host detail with the Hosts family tools. This returns matching IDs only, not the records themselves. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitstringnonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] For the provided ProcessID retrieve the process details. Discover IDs with falcon_processes_ran_on. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Find the processes associated with a given custom indicator of compromise on a specific host, and return their process IDs. Read the detail with falcon_entities_processes. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_processes to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
deviceIdstringyesRequired. Value for the Falcon device_id parameter.
limitstringnonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

MalQuery

ToolPlanAccessSummary
falcon_get_mal_query_entities_samples_fetch_v1FreeRead-onlyFetch the zip archive of MalQuery samples prepared by an earlier request, protected with the password infected.
falcon_get_mal_query_metadata_v1FreeRead-onlyRetrieve indexed files metadata by their hash.
falcon_get_mal_query_quotas_v1FreeRead-onlyGet information about search and download quotas in your environment.
falcon_get_mal_query_request_v1FreeRead-onlyCheck the status and results of an asynchronous request, such as hunt or exact-search.
falcon_post_mal_query_exact_search_v1FreeRead-onlySearch MalQuery for an exact combination of hex patterns and strings, matching samples at byte level.
falcon_post_mal_query_fuzzy_search_v1FreeRead-onlySearch MalQuery quickly for a combination of hex patterns and strings, matching samples at byte level.
falcon_post_mal_query_hunt_v1FreeRead-onlySchedule a YARA rule to run across the MalQuery corpus.

[CrowdStrike Falcon] Fetch the zip archive of MalQuery samples prepared by an earlier request, protected with the password infected. CrowdStrike serves this endpoint as a binary stream rather than JSON, so the call fails with a content type error; download the archive from the Falcon console instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Retrieve indexed files metadata by their hash. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get information about search and download quotas in your environment. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Check the status and results of an asynchronous request, such as hunt or exact-search. Supports a single request id at this time. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search MalQuery for an exact combination of hex patterns and strings, matching samples at byte level. Results can be narrowed by file type, file size and first seen date. The call returns a request ID; poll falcon_get_mal_query_request_v1 for the results. This returns matching IDs only, not the records themselves. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search MalQuery quickly for a combination of hex patterns and strings, matching samples at byte level. This is faster than the exact search and returns results directly, at the cost of more false positives. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Schedule a YARA rule to run across the MalQuery corpus. This searches CrowdStrike malware corpus, not the customer hosts. The call returns a request ID; poll falcon_get_mal_query_request_v1 for the results. This returns matching IDs only, not the records themselves. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

On-Demand Scans

ToolPlanAccessSummary
falcon_aggregate_query_scan_host_metadataFreeRead-onlyGet aggregates on ODS scan-hosts data.
falcon_aggregate_scansFreeRead-onlyGet aggregates on ODS scan data.
falcon_aggregate_scheduled_scansFreeRead-onlyGet aggregates on ODS scheduled-scan data.
falcon_cancel_scansProDestructiveCancel running on-demand scans by scan ID.
falcon_create_scanProDestructiveCreate an on-demand scan and start or schedule it for the hosts named in the request.
falcon_delete_scheduled_scansProDestructiveDelete scheduled on-demand scans by ID.
falcon_get_malicious_files_by_idsFreeRead-onlyGet malicious files by ids.
falcon_get_scan_host_metadata_by_idsFreeRead-onlyGet scan hosts by ids.
falcon_get_scans_by_scan_idsFreeRead-onlyRead full on-demand scan records for the scan IDs you supply.
falcon_get_scans_by_scan_ids_v2FreeRead-onlyGet Scans by IDs.
falcon_get_scheduled_scans_by_scan_idsFreeRead-onlyGet ScheduledScans by IDs.
falcon_query_malicious_filesFreeRead-onlyQuery malicious files.
falcon_query_scan_host_metadataFreeRead-onlyQuery scan hosts.
falcon_query_scansFreeRead-onlySearch for on-demand scan IDs with an FQL filter.
falcon_query_scheduled_scansFreeRead-onlyQuery ScheduledScans.
falcon_scans_reportProWriteLaunch a job that builds a report of on-demand scan results.
falcon_schedule_scanProDestructiveCreate a scheduled on-demand scan for the hosts named in the request.

[CrowdStrike Falcon] Get aggregates on ODS scan-hosts data. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get aggregates on ODS scan data. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get aggregates on ODS scheduled-scan data. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Cancel running on-demand scans by scan ID. Each cancelled scan stops where it is, so the hosts it had not reached are never scanned by that job. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create an on-demand scan and start or schedule it for the hosts named in the request. This dispatches real scanning work to live endpoints and consumes processor time on them for as long as the scan runs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete scheduled on-demand scans by ID. The schedule stops, so those hosts lose their recurring scan coverage until a new schedule is created. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get malicious files by ids. Discover IDs with falcon_query_malicious_files. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get scan hosts by ids. Discover IDs with falcon_query_scan_host_metadata. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read full on-demand scan records for the scan IDs you supply. Discover IDs with falcon_query_scans. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Scans by IDs. Discover IDs with falcon_query_scans. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get ScheduledScans by IDs. Discover IDs with falcon_query_scheduled_scans. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Query malicious files. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_malicious_files_by_ids to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Query scan hosts. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scan_host_metadata_by_ids to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for on-demand scan IDs with an FQL filter. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scans_by_scan_ids to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Query ScheduledScans. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scheduled_scans_by_scan_ids to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Launch a job that builds a report of on-demand scan results. The report is built from data Falcon already holds: no host is scanned and no scan is changed. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a scheduled on-demand scan for the hosts named in the request. Every run dispatches real scanning work to live endpoints and consumes processor time on them. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Quarantine

ToolPlanAccessSummary
falcon_action_update_countFreeRead-onlyReturns count of potentially affected quarantined files for each action.
falcon_get_aggregate_filesFreeRead-onlyGet quarantine file aggregates as specified via json in request body.
falcon_get_quarantine_filesFreeRead-onlyRead quarantined file metadata for the IDs you supply.
falcon_query_quarantine_filesFreeRead-onlySearch for quarantined file IDs with an FQL filter.
falcon_update_qf_by_queryProDestructiveApply an action to every quarantined file matching an FQL filter.
falcon_update_quarantined_detects_by_idsProDestructiveApply an action to quarantined files by quarantine file ID.

[CrowdStrike Falcon] Returns count of potentially affected quarantined files for each action. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.

[CrowdStrike Falcon] Get quarantine file aggregates as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read quarantined file metadata for the IDs you supply. The file content itself is not served through the API. Discover IDs with falcon_query_quarantine_files. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for quarantined file IDs with an FQL filter. Run this before any bulk quarantine action to see exactly which files the filter selects. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_quarantine_files to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Apply an action to every quarantined file matching an FQL filter. This is the bulk form of the quarantine action, so a loose filter can release or delete far more files than intended. Run the same filter through falcon_query_quarantine_files first and check the count. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_quarantine_files to read the detail. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Apply an action to quarantined files by quarantine file ID. Releasing a file returns it to the host and takes it out of quarantine, which puts a file Falcon judged malicious back into the customer environment; deleting removes it permanently. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Quick Scan

ToolPlanAccessSummary
falcon_get_scans_aggregatesFreeRead-onlyGet scans aggregations as specified via json in request body.
falcon_qscan_get_scansFreeRead-onlyCheck the status of a volume scan.
falcon_query_submissions_mixin0FreeRead-onlyFind IDs for submitted scans by providing an FQL filter and paging details.
falcon_scan_samplesProDestructiveSubmit a volume of uploaded files for machine-learning scanning.

[CrowdStrike Falcon] Get scans aggregations as specified via json in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Check the status of a volume scan. Time required for analysis increases with the number of samples in a volume but usually it should take less than 1 minute. Discover IDs with falcon_query_submissions_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Find IDs for submitted scans by providing an FQL filter and paging details. Returns a set of volume IDs that match your criteria. This returns matching IDs only, not the records themselves — pass the IDs to falcon_qscan_get_scans to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Submit a volume of uploaded files for machine-learning scanning. Analysis time grows with the number of samples in the volume and is usually under a minute. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Quick Scan Pro

ToolPlanAccessSummary
falcon_delete_fileProDestructiveDelete a QuickScan Pro file by its SHA256. The stored sample is removed, and any scan that referenced it loses its source file.
falcon_delete_scan_resultProDestructiveDelete the result of a QuickScan Pro scan.
falcon_get_scan_resultFreeRead-onlyGets the result of an QuickScan Pro scan.
falcon_launch_scanProDestructiveStart a QuickScan Pro scan of a file already uploaded through the QuickScan Pro file endpoint.
falcon_query_scan_resultsFreeRead-onlyFQL query specifying the filter parameters.
falcon_upload_file_mixin0_mixin94ProDestructiveUpload a file for QuickScan Pro analysis.
falcon_upload_file_quick_scan_proProDestructiveUpload a file for QuickScan Pro analysis, as multipart form data or as an octet stream.

[CrowdStrike Falcon] Delete a QuickScan Pro file by its SHA256. The stored sample is removed, and any scan that referenced it loses its source file. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete the result of a QuickScan Pro scan. The verdict is gone, and only a fresh scan reproduces it. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Gets the result of an QuickScan Pro scan. Discover IDs with falcon_query_scan_results. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Start a QuickScan Pro scan of a file already uploaded through the QuickScan Pro file endpoint. This detonates and analyzes the sample in CrowdStrike cloud. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] FQL query specifying the filter parameters. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scan_result to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Upload a file for QuickScan Pro analysis. The file leaves the customer environment for CrowdStrike cloud and is retained there for 90 days, which cannot be undone through the API, so confirm the customer is willing to share the artifact before you send it. Supply the file as base64 in fileContentBase64 together with its fileName. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fileContentBase64stringyesThe file content, base64-encoded.
fileNamestringyesThe file name to upload.
scanbooleannonullOptional. True or false for the Falcon scan parameter.

[CrowdStrike Falcon] Upload a file for QuickScan Pro analysis, as multipart form data or as an octet stream. The file leaves the customer environment for CrowdStrike cloud and is retained under the account retention policy, which cannot be undone through the API, so confirm the customer is willing to share the artifact before you send it. Supply the file as base64 in fileContentBase64 together with its uploadFileName. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fileContentBase64stringyesThe file content, base64-encoded.
fileNamestringnonullOptional. Value for the Falcon file_name parameter.
passwordstringnonullOptional. Value for the Falcon password parameter.
scanbooleannonullOptional. True or false for the Falcon scan parameter.
uploadFileNamestringyesThe file name to upload.

Recon

ToolPlanAccessSummary
falcon_aggregate_notifications_exposed_data_records_v1FreeRead-onlyGet notification exposed data record aggregates as specified via JSON in request body.
falcon_aggregate_notifications_v1FreeRead-onlyGet notification aggregates as specified via JSON in request body.
falcon_create_actions_v1ProWriteCreate actions for a monitoring rule.
falcon_create_export_jobs_v1ProWriteLaunch an asynchronous recon export job and return its job ID.
falcon_create_rules_v1ProWriteCreate monitoring rules.
falcon_delete_action_v1ProDestructiveDelete an action from a monitoring rule by action ID.
falcon_delete_export_jobs_v1ProDestructiveDelete recon export jobs and the files they produced, by job ID.
falcon_delete_notifications_v1ProDestructiveDelete recon notifications by ID.
falcon_delete_rules_v1ProDestructiveDelete monitoring rules by ID.
falcon_get_actions_v1FreeRead-onlyGet actions based on their IDs.
falcon_get_export_jobs_v1FreeRead-onlyGet the status of export jobs based on their IDs.
falcon_get_file_content_for_export_jobs_v1FreeRead-onlyDownload the file produced by a recon export job.
falcon_get_notifications_detailed_translated_v1FreeRead-onlyGet detailed notifications based on their IDs.
falcon_get_notifications_detailed_v1FreeRead-onlyRead recon notifications for the IDs you supply, including the raw intelligence content behind each one.
falcon_get_notifications_exposed_data_records_v1FreeRead-onlyGet notifications exposed data records based on their IDs.
falcon_get_notifications_translated_v1FreeRead-onlyGet notifications based on their IDs.
falcon_get_notifications_v1FreeRead-onlyRead recon notifications for the IDs you supply.
falcon_get_rules_v1FreeRead-onlyRead full monitoring rules for the IDs you supply.
falcon_preview_rule_v1FreeRead-onlyPreview rules notification count and distribution.
falcon_query_actions_v1FreeRead-onlyQuery actions based on provided criteria.
falcon_query_notifications_exposed_data_records_v1FreeRead-onlyQuery notifications exposed data records based on provided criteria.
falcon_query_notifications_v1FreeRead-onlySearch for recon notification IDs matching the criteria you provide.
falcon_query_rules_v1FreeRead-onlySearch for monitoring rule IDs matching the criteria you provide.
falcon_update_action_v1ProWriteUpdate an action on a monitoring rule.
falcon_update_notifications_v1ProDestructiveUpdate the status or the assignee of recon notifications, in bulk.
falcon_update_rules_v1ProDestructiveUpdate monitoring rules.

[CrowdStrike Falcon] Get notification exposed data record aggregates as specified via JSON in request body. The valid aggregation fields are: [cid notification_id notification_group_id created_date rule.id rule.name rule.topic source_category site author file.name credential_status bot.operating_system.hardware_id bot.bot_id]. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get notification aggregates as specified via JSON in request body. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create actions for a monitoring rule. Actions are the delivery channels attached to a rule; this adds them and changes no existing one. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Launch an asynchronous recon export job and return its job ID. The job reads data Falcon already holds. Poll falcon_get_export_jobs_v1 for the status, then download with falcon_get_file_content_for_export_jobs_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create monitoring rules. New rules add exposure monitoring coverage and no existing rule is changed. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete an action from a monitoring rule by action ID. The recipients that action fed stop receiving notifications for that rule. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Delete recon export jobs and the files they produced, by job ID. The exported file is no longer downloadable. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete recon notifications by ID. CrowdStrike states that notifications cannot be recovered after deletion, so the exposure record and its raw intelligence content are gone for good. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete monitoring rules by ID. Monitoring stops at once, and exposures that appear after the deletion are never reported. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
notificationsDeletionRequestedbooleannonullOptional. True or false for the Falcon notificationsDeletionRequested parameter.

[CrowdStrike Falcon] Get actions based on their IDs. IDs can be retrieved using the QueryActionsV1 endpoint. Discover IDs with falcon_query_actions_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the status of export jobs based on their IDs. Export jobs can be launched by calling CreateExportJobsV1 When a job is complete, use the job ID to download the file(s) associated with it using GET entities/export-files/v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Download the file produced by a recon export job. CrowdStrike serves this endpoint as a file stream rather than JSON, so the call fails with a content type error; download the export from the Falcon console instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get detailed notifications based on their IDs. These include the translated raw intelligence content that generated the match or part of it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read recon notifications for the IDs you supply, including the raw intelligence content behind each one. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get notifications exposed data records based on their IDs. IDs can be retrieved using the QueryNotificationsExposedDataRecordsV1 endpoint. The associate notification can be fetched using the /entities/notifications/v* endpoints. Discover IDs with falcon_query_notifications_exposed_data_records_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get notifications based on their IDs. IDs can be retrieved using the QueryNotificationsV1 endpoint. This endpoint will return translated notification content. The only target language available is English. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read recon notifications for the IDs you supply. Use falcon_get_notifications_detailed_v1 when you need the raw intelligence content behind each notification. Discover IDs with falcon_query_notifications_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Read full monitoring rules for the IDs you supply. Discover IDs with falcon_query_rules_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Preview rules notification count and distribution. This will return aggregations on: channel, count, site. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Query actions based on provided criteria. Use the IDs from this response to get the action entities on GetActionsV1. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_actions_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Query notifications exposed data records based on provided criteria. Use the IDs from this response to get the notification +entities on GetNotificationsExposedDataRecordsV1. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_notifications_exposed_data_records_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for recon notification IDs matching the criteria you provide. Read them with falcon_get_notifications_v1, or with falcon_get_notifications_detailed_v1 for the raw intelligence content. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_notifications_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for monitoring rule IDs matching the criteria you provide. Read the rules with falcon_get_rules_v1. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rules_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
secondarySortstringnonullOptional. Value for the Falcon secondarySort parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update an action on a monitoring rule. This changes the delivery channel configuration for that one rule. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update the status or the assignee of recon notifications, in bulk. Changing the status closes or reopens the exposure for every analyst in the console, and one call accepts many IDs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Update monitoring rules. A monitoring rule is live, so narrowing its terms or disabling it means exposures that would have been reported are missed from the moment the change is saved. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Sample Uploads

ToolPlanAccessSummary
falcon_archive_delete_v1ProDestructiveDelete an archive that was uploaded earlier.
falcon_archive_get_v1FreeRead-onlyRetrieves the archives upload operation statuses.
falcon_archive_list_v1FreeRead-onlyRetrieves the archives files in chunks.
falcon_archive_upload_v1ProDestructiveUpload an archive and extract its file list.
falcon_archive_upload_v2ProDestructiveUpload an archive and extract its file list.
falcon_delete_sample_v3ProDestructiveRemove a sample from the collection, including the file, its metadata and its submissions.
falcon_extraction_create_v1ProWriteExtract the files from an archive that was already uploaded and copy them into internal storage so they can be analyzed.
falcon_extraction_get_v1FreeRead-onlyRetrieves the files extraction operation statuses.
falcon_extraction_list_v1FreeRead-onlyRetrieves the files extractions in chunks.
falcon_upload_sample_v3ProDestructiveUpload a file for cloud analysis.

[CrowdStrike Falcon] Delete an archive that was uploaded earlier. The archive and the files extracted from it are removed. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Retrieves the archives upload operation statuses. Status `done` means that archive was processed successfully. Status `error` means that archive was not processed successfully. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
includeFilesbooleannonullOptional. True or false for the Falcon include_files parameter.

[CrowdStrike Falcon] Retrieves the archives files in chunks. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Upload an archive and extract its file list. The archive leaves the customer environment for CrowdStrike cloud and is retained there, which cannot be undone through the API, so confirm the customer is willing to share the artifact. The operation is asynchronous: poll falcon_archive_get_v1, then call falcon_extraction_create_v1 to copy the files into internal storage. CrowdStrike deprecates this call in favor of falcon_archive_upload_v2. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
commentstringnonullOptional audit comment recorded against this change in Falcon.
isConfidentialbooleannonullOptional. True or false for the Falcon is_confidential parameter.
namestringyesRequired. Value for the Falcon name parameter.
passwordstringnonullOptional. Value for the Falcon password parameter.

[CrowdStrike Falcon] Upload an archive and extract its file list. The archive leaves the customer environment for CrowdStrike cloud and is retained there, which cannot be undone through the API, so confirm the customer is willing to share the artifact. The operation is asynchronous: poll falcon_archive_get_v1, then call falcon_extraction_create_v1 to copy the files into internal storage. Supply the file as base64 in fileContentBase64 together with its fileName. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
fileContentBase64stringyesThe file content, base64-encoded.
fileNamestringyesThe file name to upload.
isConfidentialbooleannonullOptional. True or false for the Falcon is_confidential parameter.
namestringyesRequired. Value for the Falcon name parameter.
passwordstringnonullOptional. Value for the Falcon password parameter.

[CrowdStrike Falcon] Remove a sample from the collection, including the file, its metadata and its submissions. Nothing about the sample survives. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Extract the files from an archive that was already uploaded and copy them into internal storage so they can be analyzed. This works on content Falcon already holds and sends nothing new out of the customer environment. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Retrieves the files extraction operation statuses. Status `done` means that all files were processed successfully. Status `error` means that at least one of the file could not be processed. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
includeFilesbooleannonullOptional. True or false for the Falcon include_files parameter.

[CrowdStrike Falcon] Retrieves the files extractions in chunks. Status `done` means that all files were processed successfully. Status `error` means that at least one of the file could not be processed. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Upload a file for cloud analysis. The file leaves the customer environment for CrowdStrike cloud and is retained there, which cannot be undone through the API, so confirm the customer is willing to share the artifact before you send it. After uploading, call the analysis endpoint you need. Supply the file as base64 in fileContentBase64 together with its uploadFileName. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
commentstringnonullOptional audit comment recorded against this change in Falcon.
fileContentBase64stringyesThe file content, base64-encoded.
fileNamestringyesRequired. Value for the Falcon file_name parameter.
isConfidentialbooleannonullOptional. True or false for the Falcon is_confidential parameter.
uploadFileNamestringyesThe file name to upload.

Tailored Intelligence

ToolPlanAccessSummary
falcon_get_events_bodyFreeRead-onlyGet event body for the provided event ID.
falcon_get_events_entitiesFreeRead-onlyRead tailored intelligence events for the IDs you supply.
falcon_get_rules_entitiesFreeRead-onlyRead tailored intelligence rules for the IDs you supply.
falcon_tailored_intelligence_query_eventsFreeRead-onlySearch for tailored intelligence event IDs matching an FQL filter.
falcon_tailored_intelligence_query_rulesFreeRead-onlySearch for tailored intelligence rule IDs matching an FQL filter.

[CrowdStrike Falcon] Get event body for the provided event ID. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Read tailored intelligence events for the IDs you supply. Use falcon_get_events_body for the full event body. Discover IDs with falcon_tailored_intelligence_query_events. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Read tailored intelligence rules for the IDs you supply. Discover IDs with falcon_tailored_intelligence_query_rules. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search for tailored intelligence event IDs matching an FQL filter. Read the events with falcon_get_events_entities. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_events_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search for tailored intelligence rule IDs matching an FQL filter. Read the rules with falcon_get_rules_entities. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_rules_entities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
qstringnonullFree-text search term.
sortstringnonullSort expression, in the form property.asc or property.desc.

Threatgraph

ToolPlanAccessSummary
falcon_combined_edges_getFreeRead-onlyRead the Threat Graph edges leaving a vertex.
falcon_combined_ran_on_getFreeRead-onlyLook up where an indicator such as a hash, domain name or address has been observed running in the customer environment.
falcon_combined_summary_getFreeRead-onlyRead the Threat Graph summary for a vertex ID.
falcon_entities_vertices_getFreeRead-onlyRetrieve metadata for a ThreatGraph vertex by id.
falcon_entities_vertices_getv2FreeRead-onlyRetrieve metadata for a given vertex ID.
falcon_queries_edgetypes_getFreeRead-onlyShow all available edge types.

[CrowdStrike Falcon] Read the Threat Graph edges leaving a vertex. Exactly one edge type must be given; list the available types with falcon_queries_edgetypes_get. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
directionstringnonullOptional. Value for the Falcon direction parameter.
edgeTypestringyesRequired. Value for the Falcon edge_type parameter.
idsstringyesOne or more record IDs, comma-separated.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
nanobooleannonullOptional. True or false for the Falcon nano parameter.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
scopestringnonullOptional. Value for the Falcon scope parameter.

[CrowdStrike Falcon] Look up where an indicator such as a hash, domain name or address has been observed running in the customer environment. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
nanobooleannonullOptional. True or false for the Falcon nano parameter.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringyesRequired. Value for the Falcon type parameter.
valuestringyesRequired. Value for the Falcon value parameter.

[CrowdStrike Falcon] Read the Threat Graph summary for a vertex ID. A vertex is any observed object, such as a process, file, host or address, and the summary is the starting point for walking the graph. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
nanobooleannonullOptional. True or false for the Falcon nano parameter.
scopestringnonullOptional. Value for the Falcon scope parameter.
vertexTypestringyesThe vertex_type path value.

[CrowdStrike Falcon] Retrieve metadata for a ThreatGraph vertex by id. This is the legacy v1 surface, kept for CrowdStrike Store partners who predate the ThreatGraph OAuth2 APIs; falcon_entities_vertices_getv2 is the current one. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
nanobooleannonullOptional. True or false for the Falcon nano parameter.
scopestringnonullOptional. Value for the Falcon scope parameter.
vertexTypestringyesThe vertex_type path value.

[CrowdStrike Falcon] Retrieve metadata for a given vertex ID. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
nanobooleannonullOptional. True or false for the Falcon nano parameter.
scopestringnonullOptional. Value for the Falcon scope parameter.
vertexTypestringyesThe vertex_type path value.

[CrowdStrike Falcon] Show all available edge types. This returns matching IDs only, not the records themselves. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

Configuration Assessment

ToolPlanAccessSummary
falcon_get_combined_assessments_queryFreeRead-onlySearch Falcon configuration assessment findings by FQL filter and return the matching host findings in one call.
falcon_get_rule_detailsFreeRead-onlyGet the details of one or more configuration assessment rules by rule ID.

[CrowdStrike Falcon] Search Falcon configuration assessment findings by FQL filter and return the matching host findings in one call. A finding pairs one host with one misconfigured setting and its severity. Read the rule behind a finding with falcon_get_rule_details, and how the host was judged with falcon_get_evaluation_logic_mixin0. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
facetstringnonullOptional. One or more values, comma-separated for the Falcon facet parameter.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get the details of one or more configuration assessment rules by rule ID. The rule describes the setting being checked and why it matters. Rule IDs appear on the findings returned by falcon_get_combined_assessments_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

Configuration Assessment Evaluation Logic

ToolPlanAccessSummary
falcon_get_evaluation_logic_mixin0FreeRead-onlyGet the evaluation logic behind one or more configuration assessment findings, by finding ID.

[CrowdStrike Falcon] Get the evaluation logic behind one or more configuration assessment findings, by finding ID. This explains HOW a host was judged non-compliant. Finding IDs come from falcon_get_combined_assessments_query. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

Data Protection Configuration

ToolPlanAccessSummary
falcon_entities_classification_delete_v2ProDestructiveDelete Falcon Data Protection classifications by ID.
falcon_entities_classification_get_v2FreeRead-onlyGet Falcon Data Protection classification records by ID.
falcon_entities_classification_patch_v2ProWriteUpdate a Falcon Data Protection classification.
falcon_entities_classification_post_v2ProWriteCreate a Falcon Data Protection classification, labeling data by what it contains so policies can act on the label.
falcon_entities_cloud_application_createProWriteCreate a Falcon Data Protection cloud application - a SaaS destination policies can allow or block.
falcon_entities_cloud_application_deleteProDestructiveDelete Falcon Data Protection cloud applications by ID.
falcon_entities_cloud_application_getFreeRead-onlyGet Falcon Data Protection cloud application records by ID.
falcon_entities_cloud_application_patchProWriteUpdate a Falcon Data Protection cloud application.
falcon_entities_content_pattern_createProWriteCreate a Falcon Data Protection content pattern - the keywords or expressions a classification uses to recognize data.
falcon_entities_content_pattern_deleteProDestructiveDelete Falcon Data Protection content patterns by ID.
falcon_entities_content_pattern_getFreeRead-onlyGet Falcon Data Protection content pattern records by ID.
falcon_entities_content_pattern_patchProWriteUpdate a Falcon Data Protection content pattern.
falcon_entities_enterprise_account_createProWriteCreate a Falcon Data Protection enterprise account, identifying the customer own tenant inside a cloud application so policies can tell corporate destinations from personal ones.
falcon_entities_enterprise_account_deleteProDestructiveDelete Falcon Data Protection enterprise accounts by ID.
falcon_entities_enterprise_account_getFreeRead-onlyGet Falcon Data Protection enterprise account records by ID.
falcon_entities_enterprise_account_patchProWriteUpdate a Falcon Data Protection enterprise account.
falcon_entities_file_type_getFreeRead-onlyGet Falcon Data Protection file type records by ID.
falcon_entities_local_application_createProWriteCreate a Falcon Data Protection local application - an endpoint application policies can allow or block from handling classified data.
falcon_entities_local_application_deleteProDestructiveDelete Falcon Data Protection local applications by ID.
falcon_entities_local_application_getFreeRead-onlyGet Falcon Data Protection local application records by ID.
falcon_entities_local_application_group_createProWriteCreate a Falcon Data Protection local application group, bundling applications so one policy rule can name many.
falcon_entities_local_application_group_deleteProDestructiveDelete Falcon Data Protection local application groups by ID.
falcon_entities_local_application_group_getFreeRead-onlyGet Falcon Data Protection local application group records by ID.
falcon_entities_local_application_group_patchProWriteUpdate a Falcon Data Protection local application group.
falcon_entities_local_application_patchProWriteUpdate a Falcon Data Protection local application.
falcon_entities_policy_delete_v2ProDestructiveDelete Falcon Data Protection policies by ID.
falcon_entities_policy_get_v2FreeRead-onlyGet Falcon Data Protection policy records by ID.
falcon_entities_policy_patch_v2ProDestructiveWeakens or changes the Data Protection enforcement applied to every host in this policy's scope.
falcon_entities_policy_post_v2ProWriteCreate a Falcon Data Protection policy.
falcon_entities_policy_precedence_post_v1ProDestructiveSet the precedence order of Falcon Data Protection policies.
falcon_entities_sensitivity_label_create_v2ProWriteCreate a Falcon Data Protection sensitivity label, mirroring a label from the customer own labeling system.
falcon_entities_sensitivity_label_delete_v2ProDestructiveDelete Falcon Data Protection sensitivity labels by ID.
falcon_entities_sensitivity_label_get_v2FreeRead-onlyGet Falcon Data Protection sensitivity label records by ID.
falcon_entities_web_location_create_v2ProWriteCreate a Falcon Data Protection web location - a destination policies can allow or block.
falcon_entities_web_location_delete_v2ProDestructiveDelete Falcon Data Protection web locations by ID.
falcon_entities_web_location_get_v2FreeRead-onlyGet Falcon Data Protection web location records by ID.
falcon_entities_web_location_group_createProWriteCreate a Falcon Data Protection web location group, bundling destinations so one policy rule can name many.
falcon_entities_web_location_group_deleteProDestructiveDelete Falcon Data Protection web location groups by ID.
falcon_entities_web_location_group_getFreeRead-onlyGet Falcon Data Protection web location group records by ID.
falcon_entities_web_location_group_patchProWriteUpdate a Falcon Data Protection web location group.
falcon_entities_web_location_patch_v2ProWriteUpdate a Falcon Data Protection web location.
falcon_queries_classification_get_v2FreeRead-onlySearch Falcon Data Protection classifications by FQL filter, returning classification IDs only.
falcon_queries_cloud_application_get_v2FreeRead-onlySearch Falcon Data Protection cloud applications by FQL filter, returning application IDs only.
falcon_queries_content_pattern_get_v2FreeRead-onlySearch Falcon Data Protection content patterns by FQL filter, returning content pattern IDs only.
falcon_queries_enterprise_account_get_v2FreeRead-onlySearch Falcon Data Protection enterprise accounts by FQL filter, returning account IDs only.
falcon_queries_file_type_get_v2FreeRead-onlySearch Falcon Data Protection file types by FQL filter, returning file type IDs only.
falcon_queries_local_application_getFreeRead-onlySearch Falcon Data Protection local applications by FQL filter, returning application IDs only.
falcon_queries_local_application_group_getFreeRead-onlySearch Falcon Data Protection local application groups by FQL filter, returning group IDs only.
falcon_queries_policy_get_v2FreeRead-onlySearch Falcon Data Protection policies by FQL filter, returning policy IDs only.
falcon_queries_sensitivity_label_get_v2FreeRead-onlySearch Falcon Data Protection sensitivity labels by FQL filter, returning label IDs only.
falcon_queries_web_location_get_v2FreeRead-onlySearch Falcon Data Protection web locations by FQL filter, returning web location IDs only.
falcon_queries_web_location_group_getFreeRead-onlySearch Falcon Data Protection web location groups by FQL filter, returning group IDs only.

[CrowdStrike Falcon] Delete Falcon Data Protection classifications by ID. Data that only this classification recognized stops being labeled, so every policy that acted on the label stops acting. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection classification records by ID. A classification labels data by what it contains, and policies act on the label. Discover IDs with falcon_queries_classification_get_v2. Discover IDs with falcon_queries_classification_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection classification. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a Falcon Data Protection classification, labeling data by what it contains so policies can act on the label. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a Falcon Data Protection cloud application - a SaaS destination policies can allow or block. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection cloud applications by ID. Policy rules that named the SaaS destination lose it, which can turn a blocked destination into an allowed one. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection cloud application records by ID. A cloud application is a SaaS destination that policies allow or block data from reaching. Discover IDs with falcon_queries_cloud_application_get_v2. Discover IDs with falcon_queries_cloud_application_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection cloud application. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Create a Falcon Data Protection content pattern - the keywords or expressions a classification uses to recognize data. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection content patterns by ID. Classifications built on the pattern stop recognizing the data it matched, so the policies downstream of them stop firing. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection content pattern records by ID. A content pattern is the matcher a classification uses to recognize data. Discover IDs with falcon_queries_content_pattern_get_v2. Discover IDs with falcon_queries_content_pattern_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection content pattern. This is a partial merge - fields you omit keep their current values. Narrowing a pattern reduces what gets recognized. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Create a Falcon Data Protection enterprise account, identifying the customer own tenant inside a cloud application so policies can tell corporate destinations from personal ones. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection enterprise accounts by ID. Data Protection loses the ability to tell the customer own tenant in that cloud application from a personal one, so corporate and personal destinations stop being distinguished. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection enterprise account records by ID. An enterprise account identifies the customer own tenant inside a cloud application, so policies can tell corporate destinations from personal ones. Discover IDs with falcon_queries_enterprise_account_get_v2. Discover IDs with falcon_queries_enterprise_account_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection enterprise account. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get Falcon Data Protection file type records by ID. File types are the formats Data Protection can recognize and act on. Discover IDs with falcon_queries_file_type_get_v2. Discover IDs with falcon_queries_file_type_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a Falcon Data Protection local application - an endpoint application policies can allow or block from handling classified data. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection local applications by ID. Policy rules that named the application lose it, which can turn a restricted application into an unrestricted one. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection local application records by ID. A local application is an application installed on the endpoint that policies allow or block from handling classified data. Discover IDs with falcon_queries_local_application_get. Discover IDs with falcon_queries_local_application_get. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a Falcon Data Protection local application group, bundling applications so one policy rule can name many. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection local application groups by ID. Every policy rule that named the group loses the applications it bundled, which can turn restricted applications into unrestricted ones. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection local application group records by ID. A group bundles local applications so one policy rule can name many. Discover IDs with falcon_queries_local_application_group_get. Discover IDs with falcon_queries_local_application_group_get. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection local application group. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Update a Falcon Data Protection local application. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Delete Falcon Data Protection policies by ID. Deleting a policy removes the enforcement it provided, so the data movement it used to block or log becomes unrestricted and unrecorded. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
platformNamestringyesRequired. Value for the Falcon platform_name parameter.

[CrowdStrike Falcon] Get Falcon Data Protection policy records by ID. A Data Protection policy decides what happens when classified data moves; which policy wins for a given event is decided by precedence. Discover IDs with falcon_queries_policy_get_v2. Discover IDs with falcon_queries_policy_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Weakens or changes the Data Protection enforcement applied to every host in this policy's scope. Updates a Falcon Data Protection policy; this is a partial merge, so fields you omit keep their current values. Widening a policy reduces enforcement, so review the resulting rule set. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
platformNamestringyesRequired. Value for the Falcon platform_name parameter.

[CrowdStrike Falcon] Create a Falcon Data Protection policy. Where the new policy takes effect relative to the existing ones is decided by precedence - set that with falcon_entities_policy_precedence_post_v1. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
platformNamestringyesRequired. Value for the Falcon platform_name parameter.

[CrowdStrike Falcon] Set the precedence order of Falcon Data Protection policies. Precedence decides which policy wins when more than one matches, so a reorder can put a permissive policy above a restrictive one and silently stop enforcement across the fleet. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a Falcon Data Protection sensitivity label, mirroring a label from the customer own labeling system. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection sensitivity labels by ID. Policies keyed on the label stop matching, so data carrying it is no longer restricted. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection sensitivity label records by ID. Sensitivity labels mirror the labels applied by the customer own labeling system, such as Microsoft Purview. Discover IDs with falcon_queries_sensitivity_label_get_v2. Discover IDs with falcon_queries_sensitivity_label_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a Falcon Data Protection web location - a destination policies can allow or block. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection web locations by ID. Policy rules that named the destination lose it, which can turn a blocked destination into an allowed one. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection web location records by ID. A web location is a destination that policies allow or block data from reaching. Discover IDs with falcon_queries_web_location_get_v2. Discover IDs with falcon_queries_web_location_get_v2. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Create a Falcon Data Protection web location group, bundling destinations so one policy rule can name many. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete Falcon Data Protection web location groups by ID. Every policy rule that named the group loses the destinations it bundled, which can turn blocked destinations into allowed ones. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Falcon Data Protection web location group records by ID. A group bundles web locations so one policy rule can name many destinations. Discover IDs with falcon_queries_web_location_group_get. Discover IDs with falcon_queries_web_location_group_get. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update a Falcon Data Protection web location group. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Update a Falcon Data Protection web location. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Search Falcon Data Protection classifications by FQL filter, returning classification IDs only. Pass those IDs to falcon_entities_classification_get_v2 for the records. A classification labels data by what it contains, and policies act on the label. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_classification_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection cloud applications by FQL filter, returning application IDs only. Pass those IDs to falcon_entities_cloud_application_get for the records. A cloud application is a SaaS destination that policies allow or block data from reaching. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_cloud_application_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection content patterns by FQL filter, returning content pattern IDs only. Pass those IDs to falcon_entities_content_pattern_get for the records. A content pattern is the matcher - the keywords or expressions - a classification uses to recognize data. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_content_pattern_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection enterprise accounts by FQL filter, returning account IDs only. Pass those IDs to falcon_entities_enterprise_account_get for the records. An enterprise account identifies the customer own tenant inside a cloud application, so policies can tell corporate destinations from personal ones. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_enterprise_account_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection file types by FQL filter, returning file type IDs only. Pass those IDs to falcon_entities_file_type_get for the records. File types are the formats Data Protection can recognize and act on. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_file_type_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection local applications by FQL filter, returning application IDs only. Pass those IDs to falcon_entities_local_application_get for the records. A local application is an application installed on the endpoint that policies allow or block from handling classified data. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_local_application_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Search Falcon Data Protection local application groups by FQL filter, returning group IDs only. Pass those IDs to falcon_entities_local_application_group_get for the records. A group bundles local applications so one policy rule can name many. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_local_application_group_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Search Falcon Data Protection policies by FQL filter, returning policy IDs only. Pass those IDs to falcon_entities_policy_get_v2 for the records. A Data Protection policy decides what happens when classified data moves. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_policy_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
platformNamestringyesRequired. Value for the Falcon platform_name parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection sensitivity labels by FQL filter, returning label IDs only. Pass those IDs to falcon_entities_sensitivity_label_get_v2 for the records. Sensitivity labels mirror the labels applied by the customer own labeling system, such as Microsoft Purview. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_sensitivity_label_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Data Protection web locations by FQL filter, returning web location IDs only. Pass those IDs to falcon_entities_web_location_get_v2 for the records. A web location is a destination - a URL or domain - that policies allow or block data from reaching. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_web_location_get_v2 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
typestringnonullOptional. Value for the Falcon type parameter.

[CrowdStrike Falcon] Search Falcon Data Protection web location groups by FQL filter, returning group IDs only. Pass those IDs to falcon_entities_web_location_group_get for the records. A group bundles web locations so one policy rule can name many destinations. Data Protection keeps eleven resource types in this one service collection, so match the detail tool to the resource you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_entities_web_location_group_get to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.
typestringnonullOptional. Value for the Falcon type parameter.

Discover

ToolPlanAccessSummary
falcon_combined_applicationsFreeRead-onlySearch Falcon Discover for installed applications by FQL filter and return the full application records in one call, rather than the IDs falcon_query_applications returns.
falcon_combined_hostsFreeRead-onlySearch Falcon Discover for assets by FQL filter and return the full asset records in one call, rather than the IDs falcon_query_hosts returns.
falcon_get_accountsFreeRead-onlyGet full Falcon Discover account records for one or more account IDs, including the account type, the privilege level and the host the account was seen on.
falcon_get_applicationsFreeRead-onlyGet full Falcon Discover application records for one or more application IDs, including the vendor, the version and the assets the application is installed on.
falcon_get_hostsFreeRead-onlyGet full Falcon Discover asset records for one or more asset IDs, including the operating system, network addresses, owner and first and last seen times.
falcon_get_iot_hostsFreeRead-onlyGet full Falcon Discover IoT and operational-technology asset records for one or more asset IDs.
falcon_get_loginsFreeRead-onlyGet full Falcon Discover login records for one or more login IDs, including the account, the host and the login time.
falcon_query_accountsFreeRead-onlySearch Falcon Discover for user accounts by FQL filter, returning account IDs only.
falcon_query_applicationsFreeRead-onlySearch Falcon Discover for installed applications by FQL filter, returning application IDs only.
falcon_query_hostsFreeRead-onlySearch Falcon Discover for assets by FQL filter, returning asset IDs only.
falcon_query_iot_hostsFreeRead-onlySearch Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only.
falcon_query_iot_hosts_v2FreeRead-onlySearch Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only.
falcon_query_loginsFreeRead-onlySearch Falcon Discover for login events by FQL filter, returning login IDs only.

[CrowdStrike Falcon] Search Falcon Discover for installed applications by FQL filter and return the full application records in one call, rather than the IDs falcon_query_applications returns. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
facetstringnonullOptional. One or more values, comma-separated for the Falcon facet parameter.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 1000 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for assets by FQL filter and return the full asset records in one call, rather than the IDs falcon_query_hosts returns. Prefer this when you want the detail and do not need to page IDs separately. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
facetstringnonullOptional. One or more values, comma-separated for the Falcon facet parameter.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 1000 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get full Falcon Discover account records for one or more account IDs, including the account type, the privilege level and the host the account was seen on. Discover account IDs with falcon_query_accounts. Discover IDs with falcon_query_accounts. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full Falcon Discover application records for one or more application IDs, including the vendor, the version and the assets the application is installed on. Discover application IDs with falcon_query_applications, or get filter and detail in one call with falcon_combined_applications. Discover IDs with falcon_query_applications. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full Falcon Discover asset records for one or more asset IDs, including the operating system, network addresses, owner and first and last seen times. Discover asset IDs with falcon_query_hosts, or get filter and detail in one call with falcon_combined_hosts. Discover IDs with falcon_query_hosts. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full Falcon Discover IoT and operational-technology asset records for one or more asset IDs. These are devices Discover found on the network that cannot run a sensor, so the record is network-derived rather than agent-reported. Discover IDs with falcon_query_iot_hosts_v2. Discover IDs with falcon_query_iot_hosts. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full Falcon Discover login records for one or more login IDs, including the account, the host and the login time. Discover login IDs with falcon_query_logins. Discover IDs with falcon_query_logins. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search Falcon Discover for user accounts by FQL filter, returning account IDs only. Pass those account IDs to falcon_get_accounts for the full records. This one service collection holds four separate ID types - assets, applications, accounts and logins - each with its own detail tool, so match the detail tool to the ID type you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_accounts to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for installed applications by FQL filter, returning application IDs only. Pass those application IDs to falcon_get_applications for the full records. This one service collection holds four separate ID types - assets, applications, accounts and logins - each with its own detail tool, so match the detail tool to the ID type you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_applications to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for assets by FQL filter, returning asset IDs only. Pass those asset IDs to falcon_get_hosts for the full records. Discover covers managed, unmanaged and unsupported devices, so its inventory is wider than the sensor fleet. This one service collection holds four separate ID types - assets, applications, accounts and logins - each with its own detail tool, so match the detail tool to the ID type you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_hosts to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only. Pass those IDs to falcon_get_iot_hosts for the full records. Prefer falcon_query_iot_hosts_v2, which is the current generation of this search. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_iot_hosts to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only. Pass those IDs to falcon_get_iot_hosts for the full records. This is the current generation of the search; falcon_query_iot_hosts is the older one. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_iot_hosts to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Discover for login events by FQL filter, returning login IDs only. Pass those login IDs to falcon_get_logins for the full records. This one service collection holds four separate ID types - assets, applications, accounts and logins - each with its own detail tool, so match the detail tool to the ID type you searched. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_logins to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

Exposure Management

ToolPlanAccessSummary
falcon_aggregate_external_assetsFreeRead-onlyReturn counts and groupings over your external attack surface rather than individual assets, for example assets by country, by service or by criticality.
falcon_blob_preview_external_assetsFreeRead-onlyFetch a preview of a binary blob attached to an external asset, such as a captured screenshot or service banner.
falcon_combined_ecosystem_subsidiariesFreeRead-onlySearch your mapped subsidiaries by FQL filter and return the full records in one call, rather than the IDs falcon_query_ecosystem_subsidiaries returns.
falcon_delete_external_assetsProDestructiveRemove external assets from your external attack surface inventory by ID.
falcon_get_ecosystem_subsidiariesFreeRead-onlyGet full records for one or more ecosystem subsidiary IDs.
falcon_get_external_assetsFreeRead-onlyGet full external asset records for one or more external asset IDs, including the hostname, resolved addresses, open ports, discovered services and how CrowdStrike attributed the asset to you.
falcon_patch_external_assetsProWriteUpdate fields on existing external assets, such as criticality or ownership.
falcon_post_external_assets_inventory_v1ProWriteAdd external assets to the scanning inventory so CrowdStrike begins attributing and monitoring them.
falcon_query_ecosystem_subsidiariesFreeRead-onlySearch your mapped subsidiaries and related organizations by FQL filter, returning subsidiary IDs only.
falcon_query_external_assetsFreeRead-onlySearch your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only.
falcon_query_external_assets_v2FreeRead-onlySearch your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only.

[CrowdStrike Falcon] Return counts and groupings over your external attack surface rather than individual assets, for example assets by country, by service or by criticality. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Fetch a preview of a binary blob attached to an external asset, such as a captured screenshot or service banner. The relative link to this endpoint is returned inside a falcon_get_external_assets record. The response body is binary rather than the usual JSON envelope, so this call reports a non-JSON response instead of returning content. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
assetIdstringyesRequired. Value for the Falcon assetId parameter.
hashstringyesRequired. Value for the Falcon hash parameter.

[CrowdStrike Falcon] Search your mapped subsidiaries by FQL filter and return the full records in one call, rather than the IDs falcon_query_ecosystem_subsidiaries returns. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.
versionIdstringnonullOptional. Value for the Falcon version_id parameter.

[CrowdStrike Falcon] Remove external assets from your external attack surface inventory by ID. The assets stop being monitored and their discovered ports, services and findings drop out of Exposure Management reporting, so anything still exposed on the internet becomes invisible to you rather than protected. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full records for one or more ecosystem subsidiary IDs. A subsidiary is a related organization whose internet-facing assets roll into your external attack surface. Discover IDs with falcon_query_ecosystem_subsidiaries. Discover IDs with falcon_query_ecosystem_subsidiaries. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
versionIdstringnonullOptional. Value for the Falcon version_id parameter.

[CrowdStrike Falcon] Get full external asset records for one or more external asset IDs, including the hostname, resolved addresses, open ports, discovered services and how CrowdStrike attributed the asset to you. Discover IDs with falcon_query_external_assets_v2. Discover IDs with falcon_query_external_assets. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Update fields on existing external assets, such as criticality or ownership. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Add external assets to the scanning inventory so CrowdStrike begins attributing and monitoring them. Additive: it does not remove or overwrite existing inventory. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search your mapped subsidiaries and related organizations by FQL filter, returning subsidiary IDs only. Pass those IDs to falcon_get_ecosystem_subsidiaries for the full records. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_ecosystem_subsidiaries to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.
versionIdstringnonullOptional. Value for the Falcon version_id parameter.

[CrowdStrike Falcon] Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only. Pass those IDs to falcon_get_external_assets for the full records. Prefer falcon_query_external_assets_v2, which is the current generation of this search. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_external_assets to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only. Pass those IDs to falcon_get_external_assets for the full records. This is the current generation of the search; falcon_query_external_assets is the older one. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_external_assets to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

Falcon Complete Dashboard

ToolPlanAccessSummary
falcon_aggregate_alertsFreeRead-onlyReturn counts and groupings over endpoint protection alerts for the Falcon Complete dashboard, rather than the alert records themselves.
falcon_aggregate_allow_listFreeRead-onlyReturn counts and groupings over Falcon Complete allowlist tickets, rather than the tickets themselves.
falcon_aggregate_block_listFreeRead-onlyReturn counts and groupings over Falcon Complete blocklist tickets, rather than the tickets themselves.
falcon_aggregate_device_count_collectionFreeRead-onlyReturn host and device counts for the Falcon Complete dashboard, grouped by the criteria in the request body.
falcon_aggregate_escalationsFreeRead-onlyReturn counts and groupings over Falcon Complete escalation tickets, rather than the tickets themselves.
falcon_aggregate_fc_incidentsFreeRead-onlyDECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incident aggregates.
falcon_aggregate_prevention_policyFreeRead-onlyReturn counts and groupings over prevention policy assignment for the Falcon Complete dashboard.
falcon_aggregate_remediationsFreeRead-onlyReturn counts and groupings over Falcon Complete remediation tickets, rather than the tickets themselves.
falcon_aggregate_sensor_update_policyFreeRead-onlyReturn counts and groupings over sensor update policy assignment for the Falcon Complete dashboard.
falcon_aggregate_support_issuesFreeRead-onlyReturn counts and groupings over Falcon Complete support issue tickets, rather than the tickets themselves.
falcon_aggregate_total_device_countsFreeRead-onlyReturn the total host and device count for the Falcon Complete dashboard.
falcon_get_device_count_collection_queries_by_filterFreeRead-onlySearch Falcon Complete device count collections by FQL filter, returning collection IDs only.
falcon_query_alert_ids_by_filterFreeRead-onlySearch Falcon Complete endpoint protection alerts by FQL filter, returning alert IDs only.
falcon_query_alert_ids_by_filter_v2FreeRead-onlySearch Falcon Complete endpoint, identity and Next-Gen SIEM alerts by FQL filter, returning alert IDs only.
falcon_query_allow_list_filterFreeRead-onlySearch Falcon Complete allowlist tickets by FQL filter, returning ticket IDs only.
falcon_query_block_list_filterFreeRead-onlySearch Falcon Complete blocklist tickets by FQL filter, returning ticket IDs only.
falcon_query_escalations_filterFreeRead-onlySearch Falcon Complete escalation tickets by FQL filter, returning ticket IDs only.
falcon_query_incident_ids_by_filterFreeRead-onlyDECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incidents.
falcon_query_remediations_filterFreeRead-onlySearch Falcon Complete remediation tickets by FQL filter, returning ticket IDs only.

[CrowdStrike Falcon] Return counts and groupings over endpoint protection alerts for the Falcon Complete dashboard, rather than the alert records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over Falcon Complete allowlist tickets, rather than the tickets themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over Falcon Complete blocklist tickets, rather than the tickets themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return host and device counts for the Falcon Complete dashboard, grouped by the criteria in the request body. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over Falcon Complete escalation tickets, rather than the tickets themselves. An escalation is a case Falcon Complete analysts raised to you. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incident aggregates. The alerts collection replaced the incident API - use falcon_aggregate_alerts instead. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over prevention policy assignment for the Falcon Complete dashboard. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over Falcon Complete remediation tickets, rather than the tickets themselves. A remediation ticket records work Falcon Complete analysts performed or requested on a host. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over sensor update policy assignment for the Falcon Complete dashboard. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return counts and groupings over Falcon Complete support issue tickets, rather than the tickets themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Return the total host and device count for the Falcon Complete dashboard. Sent as a POST because the request specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search Falcon Complete device count collections by FQL filter, returning collection IDs only. Read the counts themselves with falcon_aggregate_device_count_collection. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete endpoint protection alerts by FQL filter, returning alert IDs only. Read the alert records with the Falcon alerts tools. Prefer falcon_query_alert_ids_by_filter_v2, which also covers identity and Next-Gen SIEM alerts. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete endpoint, identity and Next-Gen SIEM alerts by FQL filter, returning alert IDs only. Read the alert records with the Falcon alerts tools. This is the current generation; falcon_query_alert_ids_by_filter covers endpoint alerts only. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete allowlist tickets by FQL filter, returning ticket IDs only. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete blocklist tickets by FQL filter, returning ticket IDs only. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete escalation tickets by FQL filter, returning ticket IDs only. An escalation is a case Falcon Complete analysts raised to you. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incidents. The alerts collection replaced the incident API - use falcon_query_alert_ids_by_filter_v2 instead. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Complete remediation tickets by FQL filter, returning ticket IDs only. A remediation ticket records work Falcon Complete analysts performed or requested on a host. This returns matching IDs only, not the records themselves. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

FileVantage

ToolPlanAccessSummary
falcon_create_rule_groupsProWriteCreate a FileVantage rule group.
falcon_create_rulesProWriteCreate a rule inside a FileVantage rule group, naming the paths, file types and actions to watch.
falcon_create_scheduled_exclusionsProDestructiveBlinds FileVantage change detection for the window this exclusion covers.
falcon_delete_policiesProDestructiveDelete FileVantage policies by ID.
falcon_delete_scheduled_exclusionsProDestructiveDelete scheduled exclusions from a FileVantage policy by ID.
falcon_filevantage_create_policiesProWriteCreate a FileVantage policy.
falcon_filevantage_delete_rule_groupsProDestructiveDelete FileVantage rule groups by ID.
falcon_filevantage_delete_rulesProDestructiveDelete rules from a FileVantage rule group by ID.
falcon_filevantage_get_rule_groupsFreeRead-onlyGet the configuration of one or more FileVantage rule groups by ID, including the ids of the rules inside them.
falcon_filevantage_get_rulesFreeRead-onlyGet the configuration of one or more FileVantage rules by ID, within a rule group.
falcon_filevantage_query_rule_groupsFreeRead-onlySearch FileVantage rule groups of a given type, returning rule group IDs only.
falcon_filevantage_update_policiesProWriteUpdate a FileVantage policy.
falcon_filevantage_update_policy_precedenceProDestructiveSet the precedence order of FileVantage policies for a policy type.
falcon_filevantage_update_rulesProWriteUpdate a rule inside a FileVantage rule group.
falcon_get_actions_mixin0FreeRead-onlyGet the processing results of one or more FileVantage actions by action ID - what a previously started action did and whether it succeeded.
falcon_get_changesFreeRead-onlyGet FileVantage change records for one or more change IDs, including the host, the file or registry path, the action and the actor.
falcon_get_contentsFreeRead-onlyGet the file content FileVantage captured for one change ID, where content capture is enabled on the rule that caught it.
falcon_get_policiesFreeRead-onlyGet the configuration of one or more FileVantage policies by ID, including the assigned host groups and rule groups.
falcon_get_scheduled_exclusionsFreeRead-onlyGet the configuration of one or more scheduled exclusions from a FileVantage policy.
falcon_high_volume_query_changesFreeRead-onlySearch FileVantage changes by FQL filter, returning change IDs only, using the high-volume search that pages past the classic 10,000-record window with an after cursor.
falcon_query_actions_mixin0FreeRead-onlySearch FileVantage actions by FQL filter, returning action IDs only.
falcon_query_changesFreeRead-onlySearch FileVantage changes by FQL filter, returning change IDs only.
falcon_query_policiesFreeRead-onlySearch FileVantage policies of a given policy type, returning policy IDs only.
falcon_query_scheduled_exclusionsFreeRead-onlySearch the scheduled exclusions inside one FileVantage policy, returning exclusion IDs only.
falcon_signal_changes_externalProDestructiveInitiate FileVantage workflows for the supplied change ids.
falcon_start_actionsProDestructiveStart a FileVantage action against the supplied change ids.
falcon_update_policy_host_groupsProDestructiveAssign or unassign host groups on a FileVantage policy.
falcon_update_policy_rule_groupsProDestructiveAssign or unassign rule groups on a FileVantage policy.
falcon_update_rule_group_precedenceProDestructiveSet the precedence order of the rules inside a FileVantage rule group.
falcon_update_rule_groupsProWriteUpdate a FileVantage rule group.
falcon_update_scheduled_exclusionsProDestructiveBlinds FileVantage change detection for the window this exclusion covers.

[CrowdStrike Falcon] Create a FileVantage rule group. A new rule group watches nothing until you add rules with falcon_create_rules and attach the group to a policy with falcon_update_policy_rule_groups. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a rule inside a FileVantage rule group, naming the paths, file types and actions to watch. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Blinds FileVantage change detection for the window this exclusion covers. Creates a scheduled exclusion on a FileVantage policy, so file and registry changes made inside that window, on every host the policy covers, go unrecorded. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete FileVantage policies by ID. Every host group assigned to a deleted policy stops being monitored for file and registry changes, and the policy rule assignments and scheduled exclusions go with it. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete scheduled exclusions from a FileVantage policy by ID. The maintenance windows they covered stop being suppressed, so change volume on those hosts rises. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
policyIdstringyesRequired. Value for the Falcon policy_id parameter.

[CrowdStrike Falcon] Create a FileVantage policy. A new policy monitors nothing until you assign host groups with falcon_update_policy_host_groups and rule groups with falcon_update_policy_rule_groups. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete FileVantage rule groups by ID. Every rule inside the group is removed and every policy that used the group stops watching the paths it covered, so monitored hosts silently lose that coverage. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Delete rules from a FileVantage rule group by ID. The paths and file types the rule watched stop being monitored on every host under a policy that uses this rule group. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
ruleGroupIdstringyesRequired. Value for the Falcon rule_group_id parameter.

[CrowdStrike Falcon] Get the configuration of one or more FileVantage rule groups by ID, including the ids of the rules inside them. Discover IDs with falcon_filevantage_query_rule_groups, then read an individual rule with falcon_filevantage_get_rules. Discover IDs with falcon_filevantage_query_rule_groups. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the configuration of one or more FileVantage rules by ID, within a rule group. A rule names the paths, file types and actions FileVantage watches. Rule ids are listed on the rule group record returned by falcon_filevantage_get_rule_groups. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
ruleGroupIdstringyesRequired. Value for the Falcon rule_group_id parameter.

[CrowdStrike Falcon] Search FileVantage rule groups of a given type, returning rule group IDs only. Pass those IDs to falcon_filevantage_get_rule_groups for the records. This returns matching IDs only, not the records themselves — pass the IDs to falcon_filevantage_get_rule_groups to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.
typestringyesRequired. Value for the Falcon type parameter.

[CrowdStrike Falcon] Update a FileVantage policy. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Set the precedence order of FileVantage policies for a policy type. Precedence decides which policy wins for a host matching more than one, so a reorder can move hosts onto a different monitoring configuration in a single call, including one that watches less. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
typestringyesRequired. Value for the Falcon type parameter.

[CrowdStrike Falcon] Update a rule inside a FileVantage rule group. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get the processing results of one or more FileVantage actions by action ID - what a previously started action did and whether it succeeded. Discover IDs with falcon_query_actions_mixin0. Discover IDs with falcon_query_actions_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get FileVantage change records for one or more change IDs, including the host, the file or registry path, the action and the actor. A change is a detected modification event on a monitored host. Discover IDs with falcon_query_changes, or with falcon_high_volume_query_changes on busy tenants. Discover IDs with falcon_high_volume_query_changes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the file content FileVantage captured for one change ID, where content capture is enabled on the rule that caught it. Change IDs come from falcon_query_changes. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get the configuration of one or more FileVantage policies by ID, including the assigned host groups and rule groups. Discover IDs with falcon_query_policies. Discover IDs with falcon_query_policies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the configuration of one or more scheduled exclusions from a FileVantage policy. A scheduled exclusion suppresses change detection during a maintenance window. Discover IDs with falcon_query_scheduled_exclusions. Discover IDs with falcon_query_scheduled_exclusions. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
policyIdstringyesRequired. Value for the Falcon policy_id parameter.

[CrowdStrike Falcon] Search FileVantage changes by FQL filter, returning change IDs only, using the high-volume search that pages past the classic 10,000-record window with an after cursor. Prefer this over falcon_query_changes on busy tenants. Pass the IDs to falcon_get_changes for the records. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_changes to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search FileVantage actions by FQL filter, returning action IDs only. Pass those IDs to falcon_get_actions_mixin0 for the processing results. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_actions_mixin0 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 500 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search FileVantage changes by FQL filter, returning change IDs only. Pass those IDs to falcon_get_changes for the records. A FileVantage change is a detected file or registry modification event on a monitored host, not a configuration change you made. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_changes to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search FileVantage policies of a given policy type, returning policy IDs only. Pass those IDs to falcon_get_policies for the records. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_policies to read the detail. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.
typestringyesRequired. Value for the Falcon type parameter.

[CrowdStrike Falcon] Search the scheduled exclusions inside one FileVantage policy, returning exclusion IDs only. Pass those IDs to falcon_get_scheduled_exclusions for the records. A scheduled exclusion suppresses change detection during a maintenance window. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scheduled_exclusions to read the detail. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
policyIdstringyesRequired. Value for the Falcon policy_id parameter.

[CrowdStrike Falcon] Initiate FileVantage workflows for the supplied change ids. This dispatches the configured workflow against live hosts and any downstream integration, so it takes effect outside Falcon as well as inside it. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Start a FileVantage action against the supplied change ids. The action runs against live monitored hosts, so this dispatches real work rather than recording an intent. Check the outcome with falcon_get_actions_mixin0. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Assign or unassign host groups on a FileVantage policy. Hosts in a group you unassign stop being monitored for file and registry changes by that policy, which removes coverage from live machines rather than adding it. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionstringyesRequired. Value for the Falcon action parameter.
idsstringyesOne or more record IDs, comma-separated.
policyIdstringyesRequired. Value for the Falcon policy_id parameter.

[CrowdStrike Falcon] Assign or unassign rule groups on a FileVantage policy. A rule group you unassign stops being applied to the policy hosts, so the paths it watched are no longer monitored on those machines. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actionstringyesRequired. Value for the Falcon action parameter.
idsstringyesOne or more record IDs, comma-separated.
policyIdstringyesRequired. Value for the Falcon policy_id parameter.

[CrowdStrike Falcon] Set the precedence order of the rules inside a FileVantage rule group. Precedence decides which rule wins for a path matched by more than one, so a reorder can change which paths are watched and which are excluded. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.
ruleGroupIdstringyesRequired. Value for the Falcon rule_group_id parameter.

[CrowdStrike Falcon] Update a FileVantage rule group. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Blinds FileVantage change detection for the window this exclusion covers. Updates a scheduled exclusion on a FileVantage policy; this is a partial merge, so fields you omit keep their current values. Widening the window leaves more change activity unrecorded. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Global Configs

ToolPlanAccessSummary
falcon_get_global_configsFreeRead-onlyGet the tenant-wide network scan configuration for this customer ID, such as default scan windows and global exclusions.
falcon_update_global_configsProWriteUpdate the tenant-wide network scan configuration for this customer ID.

[CrowdStrike Falcon] Get the tenant-wide network scan configuration for this customer ID, such as default scan windows and global exclusions. It takes no IDs - there is one global config per CID. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Update the tenant-wide network scan configuration for this customer ID. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Networks

ToolPlanAccessSummary
falcon_aggregate_networksFreeRead-onlyReturn counts and groupings over network scan targets, rather than the records themselves.
falcon_create_networksProWriteCreate network scan targets - the address ranges a scanner is allowed to scan.
falcon_delete_networksProDestructiveDelete network scan targets by ID.
falcon_get_networksFreeRead-onlyGet network scan target records by ID, including the address ranges and the zone they belong to.
falcon_query_networksFreeRead-onlySearch network scan targets by FQL filter, returning network IDs only.
falcon_update_networksProWriteUpdate network scan targets.

[CrowdStrike Falcon] Return counts and groupings over network scan targets, rather than the records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create network scan targets - the address ranges a scanner is allowed to scan. Creating a target does not itself start a scan. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete network scan targets by ID. Every scan that referenced the address range stops covering it, so the hosts inside it silently drop out of vulnerability results rather than being reported as clean. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get network scan target records by ID, including the address ranges and the zone they belong to. A network is an address range the scanner is allowed to scan. Discover IDs with falcon_query_networks. Discover IDs with falcon_query_networks. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search network scan targets by FQL filter, returning network IDs only. Pass those IDs to falcon_get_networks for the records. A network here is an address range the scanner is allowed to scan, not a discovered device. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_networks to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update network scan targets. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Scan Run Reports

ToolPlanAccessSummary
falcon_get_scan_run_reportsFreeRead-onlyDownload the report for a network scan run.

[CrowdStrike Falcon] Download the report for a network scan run. CrowdStrike returns this report as CSV rather than JSON, so the call reports a non-JSON response instead of returning the report content. Read the run summary with falcon_get_scan_runs instead. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

Network Scan Scan Runs

ToolPlanAccessSummary
falcon_aggregate_scan_runsFreeRead-onlyReturn counts and groupings over network scan runs, rather than the records themselves.
falcon_create_scan_runsProDestructiveStart a network scan run - one immediate execution of a scan definition.
falcon_get_scan_runsFreeRead-onlyGet network scan run records by ID, including the status, the timing and the findings summary of that execution.
falcon_query_scan_runsFreeRead-onlySearch network scan runs by FQL filter, returning scan run IDs only.
falcon_update_scan_runsProWriteUpdate a network scan run in flight, for example to change its state.

[CrowdStrike Falcon] Return counts and groupings over network scan runs, rather than the records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Start a network scan run - one immediate execution of a scan definition. THIS SENDS REAL SCANNING TRAFFIC ACROSS THE CUSTOMER NETWORK and can trip intrusion detection and disturb fragile devices, so confirm the target ranges and the timing with the customer first. Track the run with falcon_get_scan_runs. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get network scan run records by ID, including the status, the timing and the findings summary of that execution. Discover IDs with falcon_query_scan_runs, and read the definition behind a run with falcon_netscan_get_scans. Discover IDs with falcon_query_scan_runs. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search network scan runs by FQL filter, returning scan run IDs only. Pass those IDs to falcon_get_scan_runs for the records. A scan run is one execution of a scan definition. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scan_runs to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update a network scan run in flight, for example to change its state. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Scanners

ToolPlanAccessSummary
falcon_aggregate_scannersFreeRead-onlyReturn counts and groupings over deployed network scanners, rather than the records themselves.
falcon_get_scannersFreeRead-onlyGet network scanner records by ID, including the host running the scanner, its version and its health.
falcon_query_scannersFreeRead-onlySearch deployed network scanners by FQL filter, returning scanner IDs only.
falcon_update_scannersProWriteUpdate the configuration of a deployed network scanner.

[CrowdStrike Falcon] Return counts and groupings over deployed network scanners, rather than the records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Get network scanner records by ID, including the host running the scanner, its version and its health. A scanner is a deployed collector host that performs the scanning. Discover IDs with falcon_query_scanners. Discover IDs with falcon_query_scanners. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search deployed network scanners by FQL filter, returning scanner IDs only. Pass those IDs to falcon_get_scanners for the records. A scanner is a deployed collector host that performs the scanning; it is not a scan or a scan result. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_scanners to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update the configuration of a deployed network scanner. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Scans

ToolPlanAccessSummary
falcon_aggregate_scans_mixin0FreeRead-onlyReturn counts and groupings over network scan definitions, rather than the records themselves.
falcon_create_scansProDestructiveCreate a network scan definition - target networks, template and schedule.
falcon_delete_scansProDestructiveDelete network scan definitions by ID.
falcon_netscan_get_scansFreeRead-onlyGet network scan definition records by ID, including the target networks, the template and the schedule.
falcon_query_scans_mixin0FreeRead-onlySearch network scan definitions by FQL filter, returning scan IDs only.
falcon_update_scansProWriteUpdate a network scan definition.

[CrowdStrike Falcon] Return counts and groupings over network scan definitions, rather than the records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Create a network scan definition - target networks, template and schedule. THIS SENDS REAL SCANNING TRAFFIC ACROSS THE CUSTOMER NETWORK: a scan can begin as soon as it is created, and active scanning can trip intrusion detection and disturb fragile devices. Confirm the target ranges and the scan window with the customer before creating one. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete network scan definitions by ID. The schedule stops, the target address ranges stop being scanned, and the vulnerability findings for those hosts stop refreshing. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get network scan definition records by ID, including the target networks, the template and the schedule. Each execution of a scan is a separate scan run - list those with falcon_query_scan_runs. Discover scan IDs with falcon_query_scans_mixin0. Discover IDs with falcon_query_scans_mixin0. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search network scan definitions by FQL filter, returning scan IDs only. Pass those IDs to falcon_netscan_get_scans for the records. A scan is the definition - target networks, template and schedule; each execution of it is a separate scan run. This returns matching IDs only, not the records themselves — pass the IDs to falcon_netscan_get_scans to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update a network scan definition. This is a partial merge - fields you omit keep their current values. Changing the schedule or the target networks changes what gets scanned and when. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Templates

ToolPlanAccessSummary
falcon_create_templatesProWriteCreate a reusable network scan template - what to probe and how aggressively.
falcon_delete_templatesProDestructiveDelete network scan templates by ID.
falcon_get_template_configsFreeRead-onlyGet the setting detail behind the network scan templates - the individual probes and options a template turns on.
falcon_get_templatesFreeRead-onlyGet network scan template records by ID.
falcon_query_templatesFreeRead-onlySearch network scan templates by FQL filter, returning template IDs only.
falcon_update_templatesProWriteUpdate a network scan template.

[CrowdStrike Falcon] Create a reusable network scan template - what to probe and how aggressively. A template does nothing until a scan references it. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete network scan templates by ID. Every scan that referenced the template loses its probe configuration, so those scans stop producing the results they were built for. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get the setting detail behind the network scan templates - the individual probes and options a template turns on. Read the templates themselves with falcon_get_templates. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Get network scan template records by ID. A template is a reusable scan configuration that scans reference. Discover IDs with falcon_query_templates, and read the per-template setting detail with falcon_get_template_configs. Discover IDs with falcon_query_templates. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search network scan templates by FQL filter, returning template IDs only. Pass those IDs to falcon_get_templates for the records. A template is a reusable scan configuration - what to probe and how aggressively - that scans reference. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_templates to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update a network scan template. This is a partial merge - fields you omit keep their current values. The change takes effect on every scan that references the template. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

Network Scan Zones

ToolPlanAccessSummary
falcon_aggregate_zonesFreeRead-onlyReturn counts and groupings over network scan zones, rather than the records themselves.
falcon_combined_zonesFreeRead-onlySearch network scan zones by FQL filter and return the full zone records in one call, rather than the IDs falcon_query_zones returns.
falcon_create_zonesProWriteCreate a network scan zone, grouping address ranges with the scanners allowed to reach them.
falcon_delete_zonesProDestructiveDelete network scan zones by ID.
falcon_get_zonesFreeRead-onlyGet network scan zone records by ID.
falcon_query_zonesFreeRead-onlySearch network scan zones by FQL filter, returning zone IDs only.
falcon_update_zonesProWriteUpdate a network scan zone.

[CrowdStrike Falcon] Return counts and groupings over network scan zones, rather than the records themselves. Sent as a POST because the aggregation specification travels in the request body; it reads and changes nothing. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Search network scan zones by FQL filter and return the full zone records in one call, rather than the IDs falcon_query_zones returns. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Create a network scan zone, grouping address ranges with the scanners allowed to reach them. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Delete network scan zones by ID. The networks and scanners grouped by the zone lose that association, so scans that relied on it stop reaching their targets. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get network scan zone records by ID. A zone groups address ranges with the scanners allowed to reach them. Discover IDs with falcon_query_zones. Discover IDs with falcon_query_zones. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search network scan zones by FQL filter, returning zone IDs only. Pass those IDs to falcon_get_zones for the records. A zone groups networks with the scanners allowed to reach them. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_zones to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
filterstringnonullFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Update a network scan zone. This is a partial merge - fields you omit keep their current values. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

SaaS Security

ToolPlanAccessSummary
falcon_dismiss_affected_entity_v3ProWriteDismiss one affected entity from a SaaS Security posture check, suppressing that entity from the check results.
falcon_dismiss_security_check_v3ProWriteDismiss a SaaS Security posture check by ID, suppressing it from the posture view.
falcon_get_activity_monitor_v3FreeRead-onlyGet the SaaS Security activity feed - user and administrator actions recorded in connected SaaS applications.
falcon_get_alerts_v3FreeRead-onlyGet SaaS Security alerts - one alert by ID, or the list.
falcon_get_app_inventoryFreeRead-onlyGet the inventory of SaaS applications CrowdStrike discovered in this tenant, sanctioned and unsanctioned.
falcon_get_app_inventory_usersFreeRead-onlyGet the users of a discovered SaaS application, including how they signed in and when they were last active.
falcon_get_asset_inventory_v3FreeRead-onlyGet the SaaS Security data inventory - the files and data objects held in connected SaaS applications, with their sensitivity classification.
falcon_get_device_inventory_v3FreeRead-onlyGet the SaaS Security device inventory - the devices seen accessing connected SaaS applications.
falcon_get_integrations_v3FreeRead-onlyGet the SaaS application integrations connected to SaaS Security, with their connection status.
falcon_get_metrics_v3FreeRead-onlyGet the SaaS Security summary metrics - the rollup counters behind the posture dashboard, such as open checks by severity.
falcon_get_security_check_affected_v3FreeRead-onlyGet the accounts, users or resources a SaaS Security posture check flagged.
falcon_get_security_check_compliance_v3FreeRead-onlyGet the compliance framework mappings for SaaS Security posture checks - which control in which standard each check satisfies.
falcon_get_security_checks_v3FreeRead-onlyGet SaaS Security posture checks - one check by ID, or the list of checks.
falcon_get_supported_saas_v3FreeRead-onlyGet the catalog of SaaS applications SaaS Security can connect to.
falcon_get_system_logs_v3FreeRead-onlyGet the SaaS Security system log - the audit trail of SaaS Security own activity, such as connector runs and configuration changes.
falcon_get_system_users_v3FreeRead-onlyGet the SaaS Security system users - the accounts that administer SaaS Security itself, not the users of the connected applications.
falcon_get_user_inventory_v3FreeRead-onlyGet the SaaS Security user inventory - the identities seen across connected SaaS applications, with their roles and privilege level.
falcon_integration_builder_end_transaction_v3ProWriteClose an open custom SaaS Security integration data upload transaction, committing what was uploaded.
falcon_integration_builder_get_status_v3FreeRead-onlyGet the status of a custom SaaS Security integration build, including how far an in-progress data upload transaction has reached.
falcon_integration_builder_reset_v3ProDestructiveReset a custom SaaS Security integration, discarding its in-progress state and any uploaded data that was not committed.
falcon_integration_builder_upload_v3ProWriteUpload data into an open custom SaaS Security integration transaction.

[CrowdStrike Falcon] Dismiss one affected entity from a SaaS Security posture check, suppressing that entity from the check results. The underlying misconfiguration is not fixed - only the reporting of it stops. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Dismiss a SaaS Security posture check by ID, suppressing it from the posture view. The underlying misconfiguration is not fixed - only the reporting of it stops. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get the SaaS Security activity feed - user and administrator actions recorded in connected SaaS applications. Use limit to bound the response size. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
actorstringnonullOptional. Value for the Falcon actor parameter.
categorystringnonullOptional. Value for the Falcon category parameter.
fromDatestringnonullOptional. Value for the Falcon from_date parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
projectionstringnonullOptional. Value for the Falcon projection parameter.
skipintegernonullOptional. Numeric value for the Falcon skip parameter.
toDatestringnonullOptional. Value for the Falcon to_date parameter.

[CrowdStrike Falcon] Get SaaS Security alerts - one alert by ID, or the list. These are alerts raised on connected SaaS applications, separate from endpoint alerts. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
ascendingbooleannonullOptional. True or false for the Falcon ascending parameter.
fromDatestringnonullOptional. Value for the Falcon from_date parameter.
idstringnonullOptional. Value for the Falcon id parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
lastIdstringnonullOptional. Value for the Falcon last_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
toDatestringnonullOptional. Value for the Falcon to_date parameter.
typestringnonullOptional. Value for the Falcon type parameter.

[CrowdStrike Falcon] Get the inventory of SaaS applications CrowdStrike discovered in this tenant, sanctioned and unsanctioned. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
accessLevelstringnonullOptional. Value for the Falcon access_level parameter.
groupsstringnonullOptional. Value for the Falcon groups parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
lastActivitystringnonullOptional. Value for the Falcon last_activity parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
scopesstringnonullOptional. Value for the Falcon scopes parameter.
statusstringnonullOptional. Value for the Falcon status parameter.
typestringnonullOptional. Value for the Falcon type parameter.
usersstringnonullOptional. Value for the Falcon users parameter.

[CrowdStrike Falcon] Get the users of a discovered SaaS application, including how they signed in and when they were last active. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
itemIdstringyesRequired. Value for the Falcon item_id parameter.

[CrowdStrike Falcon] Get the SaaS Security data inventory - the files and data objects held in connected SaaS applications, with their sensitivity classification. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
accessLevelstringnonullOptional. Value for the Falcon access_level parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
lastAccessedstringnonullOptional. Value for the Falcon last_accessed parameter.
lastModifiedstringnonullOptional. Value for the Falcon last_modified parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
passwordProtectedbooleannonullOptional. True or false for the Falcon password_protected parameter.
resourceNamestringnonullOptional. Value for the Falcon resource_name parameter.
resourceOwnerstringnonullOptional. Value for the Falcon resource_owner parameter.
resourceOwnerEnabledbooleannonullOptional. True or false for the Falcon resource_owner_enabled parameter.
resourceTypestringnonullOptional. Value for the Falcon resource_type parameter.
unmanagedDomainstringnonullOptional. Value for the Falcon unmanaged_domain parameter.

[CrowdStrike Falcon] Get the SaaS Security device inventory - the devices seen accessing connected SaaS applications. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
emailstringnonullOptional. Value for the Falcon email parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
privilegedOnlybooleannonullOptional. True or false for the Falcon privileged_only parameter.
unassociatedDevicesbooleannonullOptional. True or false for the Falcon unassociated_devices parameter.

[CrowdStrike Falcon] Get the SaaS application integrations connected to SaaS Security, with their connection status. Read this first to learn which applications are actually being assessed before you interpret any finding. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
saasIdstringnonullOptional. Value for the Falcon saas_id parameter.

[CrowdStrike Falcon] Get the SaaS Security summary metrics - the rollup counters behind the posture dashboard, such as open checks by severity. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
checkTypestringnonullOptional. Value for the Falcon check_type parameter.
compliancebooleannonullOptional. True or false for the Falcon compliance parameter.
impactstringnonullOptional. Value for the Falcon impact parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
statusstringnonullOptional. Value for the Falcon status parameter.

[CrowdStrike Falcon] Get the accounts, users or resources a SaaS Security posture check flagged. Read the check itself with falcon_get_security_checks_v3. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.

[CrowdStrike Falcon] Get the compliance framework mappings for SaaS Security posture checks - which control in which standard each check satisfies. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get SaaS Security posture checks - one check by ID, or the list of checks. A check is a configuration test CrowdStrike runs against a connected SaaS application, so its result is a posture finding rather than a detection. Read who is affected with falcon_get_security_check_affected_v3. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
checkTagsstringnonullOptional. Value for the Falcon check_tags parameter.
checkTypestringnonullOptional. Value for the Falcon check_type parameter.
compliancebooleannonullOptional. True or false for the Falcon compliance parameter.
idstringnonullOptional. Value for the Falcon id parameter.
impactstringnonullOptional. Value for the Falcon impact parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
statusstringnonullOptional. Value for the Falcon status parameter.

[CrowdStrike Falcon] Get the catalog of SaaS applications SaaS Security can connect to. This is what is SUPPORTED, not what this tenant has connected - for that use falcon_get_integrations_v3. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Get the SaaS Security system log - the audit trail of SaaS Security own activity, such as connector runs and configuration changes. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
fromDatestringnonullOptional. Value for the Falcon from_date parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
toDatestringnonullOptional. Value for the Falcon to_date parameter.
totalCountbooleannonullOptional. True or false for the Falcon total_count parameter.

[CrowdStrike Falcon] Get the SaaS Security system users - the accounts that administer SaaS Security itself, not the users of the connected applications. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

[CrowdStrike Falcon] Get the SaaS Security user inventory - the identities seen across connected SaaS applications, with their roles and privilege level. Paged with offset and limit. CrowdStrike caps classic offset paging at a 10,000-record window (offset + limit), so narrow the filter rather than paging past it. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
emailstringnonullOptional. Value for the Falcon email parameter.
integrationIdstringnonullOptional. Value for the Falcon integration_id parameter.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
offsetintegernonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
privilegedOnlybooleannonullOptional. True or false for the Falcon privileged_only parameter.

[CrowdStrike Falcon] Close an open custom SaaS Security integration data upload transaction, committing what was uploaded. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Get the status of a custom SaaS Security integration build, including how far an in-progress data upload transaction has reached. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Reset a custom SaaS Security integration, discarding its in-progress state and any uploaded data that was not committed. There is no undo - the transaction has to be rebuilt from the start. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Upload data into an open custom SaaS Security integration transaction. Additive within the transaction; close it with falcon_integration_builder_end_transaction_v3. Supply bodyJson as a JSON object matching the Falcon request body for this operation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.
idstringyesRequired. Value for the Falcon id parameter.
sourceIdstringyesRequired. Value for the Falcon source_id parameter.

Spotlight Evaluation Logic

ToolPlanAccessSummary
falcon_combined_query_evaluation_logicFreeRead-onlySearch Spotlight evaluation logic by FQL filter and return the full records in one call, rather than the IDs falcon_query_evaluation_logic returns.
falcon_combined_supported_evaluation_extFreeRead-onlySearch and return the evaluation types Spotlight supports, in one call.
falcon_get_evaluation_logicFreeRead-onlyGet Spotlight evaluation logic records by ID.
falcon_query_evaluation_logicFreeRead-onlySearch Spotlight evaluation logic by FQL filter, returning evaluation logic IDs only.

[CrowdStrike Falcon] Search Spotlight evaluation logic by FQL filter and return the full records in one call, rather than the IDs falcon_query_evaluation_logic returns. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search and return the evaluation types Spotlight supports, in one call. This is a catalog of what CAN be evaluated, not the findings for your environment. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 400 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
riskProviderstringnonullOptional. One or more values, comma-separated for the Falcon risk_provider parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get Spotlight evaluation logic records by ID. Evaluation logic is the rule Spotlight applied to decide a host is vulnerable, so this is the tool that explains WHY a finding exists. Discover IDs with falcon_query_evaluation_logic. Discover IDs with falcon_query_evaluation_logic. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search Spotlight evaluation logic by FQL filter, returning evaluation logic IDs only. Pass those IDs to falcon_get_evaluation_logic for the records. Evaluation logic is the rule Spotlight applied to decide a host is vulnerable, so it is what you read to explain or dispute a finding. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_evaluation_logic to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

Spotlight Vulnerabilities

ToolPlanAccessSummary
falcon_combined_query_installed_patchesFreeRead-onlyDECOMMISSIONED: CrowdStrike retired this operation and it no longer returns installed-patch data for hosts.
falcon_combined_query_vulnerabilitiesFreeRead-onlySearch Falcon Spotlight for vulnerabilities by FQL filter and return the full vulnerability records in one call, rather than the IDs falcon_spotlight_query_vulnerabilities returns.
falcon_get_remediationsFreeRead-onlyGet Spotlight remediation records by ID, first generation.
falcon_get_remediations_v2FreeRead-onlyGet Spotlight remediation records by ID.
falcon_spotlight_get_vulnerabilitiesFreeRead-onlyGet full Spotlight vulnerability records for one or more vulnerability IDs, including the affected host, the CVE, the severity and the ids of the recommended remediations.
falcon_spotlight_query_vulnerabilitiesFreeRead-onlySearch Falcon Spotlight for vulnerabilities across your managed hosts by FQL filter, returning vulnerability IDs only.

[CrowdStrike Falcon] DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns installed-patch data for hosts. Use falcon_combined_query_vulnerabilities instead. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 100 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Search Falcon Spotlight for vulnerabilities by FQL filter and return the full vulnerability records in one call, rather than the IDs falcon_spotlight_query_vulnerabilities returns. Prefer this when you want the detail and do not need to page IDs separately. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
facetstringnonullOptional. One or more values, comma-separated for the Falcon facet parameter.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 5000 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get Spotlight remediation records by ID, first generation. A Spotlight remediation is a RECOMMENDED FIX description, not an action - reading it changes nothing. Prefer falcon_get_remediations_v2, which is the current generation. Remediation IDs come from the remediation block of a vulnerability record returned by falcon_spotlight_get_vulnerabilities. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get Spotlight remediation records by ID. A Spotlight remediation is a RECOMMENDED FIX description - the patch or configuration change that would close a vulnerability. It is reference data: reading it changes nothing, and StackJack ships no tool that applies one. Remediation IDs come from the remediation block of a vulnerability record returned by falcon_spotlight_get_vulnerabilities. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Get full Spotlight vulnerability records for one or more vulnerability IDs, including the affected host, the CVE, the severity and the ids of the recommended remediations. Discover vulnerability IDs with falcon_spotlight_query_vulnerabilities, then read the recommended fixes with falcon_get_remediations_v2. Discover IDs with falcon_spotlight_query_vulnerabilities. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Search Falcon Spotlight for vulnerabilities across your managed hosts by FQL filter, returning vulnerability IDs only. Pass those IDs to falcon_spotlight_get_vulnerabilities for the full records. This service collection also holds remediation records under their own separate IDs, so use the vulnerability detail tool here, not the remediation one. This returns matching IDs only, not the records themselves — pass the IDs to falcon_spotlight_get_vulnerabilities to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 400 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

Spotlight Vulnerability Metadata

ToolPlanAccessSummary
falcon_combine_vuln_metadata_extFreeRead-onlySearch Spotlight vulnerability metadata and return the matching records in one call.

[CrowdStrike Falcon] Search Spotlight vulnerability metadata and return the matching records in one call. This is CVE-level reference data - CVSS scores, exploit status and the CrowdStrike ExPRT.AI rating - describing a vulnerability in general. It does NOT say which of your hosts are affected; for that use falcon_combined_query_vulnerabilities. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. This endpoint also accepts a legacy offset parameter, which is bound by CrowdStrike's 10,000-record window (offset + limit); the cursor is not, so prefer the cursor for anything that might run long. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 400 for this endpoint; larger values are reduced to it.
offsetstringnonullZero-based record offset. CrowdStrike caps offset + limit at 10,000 records; past that, use an endpoint with an after cursor.
riskProviderstringnonullOptional. One or more values, comma-separated for the Falcon risk_provider parameter.
sortstringnonullSort expression, in the form property.asc or property.desc.

Zero Trust Assessment

ToolPlanAccessSummary
falcon_get_assessment_v1FreeRead-onlyGet Zero Trust Assessment scores for specific hosts, by agent ID (AID) and customer ID (CID).
falcon_get_assessments_by_score_v1FreeRead-onlyFind hosts whose Zero Trust Assessment score falls in a range, for one customer ID (CID).
falcon_get_audit_v1FreeRead-onlyGet the Zero Trust Assessment audit report for one customer ID (CID) - the tenant-wide rollup of assessment coverage and scoring rather than per-host detail.

[CrowdStrike Falcon] Get Zero Trust Assessment scores for specific hosts, by agent ID (AID) and customer ID (CID). The assessment scores a host on its sensor and operating system configuration, so it is a posture score rather than a detection. Find the hosts in a score range with falcon_get_assessments_by_score_v1. Discover IDs with falcon_get_assessments_by_score_v1. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idsstringyesOne or more record IDs, comma-separated.

[CrowdStrike Falcon] Find hosts whose Zero Trust Assessment score falls in a range, for one customer ID (CID). Returns the hosts with their scores, so this is where to start when hunting the weakest-configured machines. Read one known host with falcon_get_assessment_v1. This returns matching IDs only, not the records themselves — pass the IDs to falcon_get_assessment_v1 to read the detail. The filter parameter uses CrowdStrike FQL (Falcon Query Language), not OData or JMESPath: property:'value', joined with + for AND and , for OR, and comparison via :> :< :>= :<= (for example platform_name:'Windows'+last_seen:>'now-7d'). Quote string values with single quotes. Paged with an after cursor taken from meta.pagination.after on the previous response. Prefer the cursor over offset — it is the only paging model that reaches past 10,000 records. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
afterstringnonullPagination cursor from meta.pagination.after on the previous response. Leave unset for the first page.
filterstringyesFQL filter expression, for example platform_name:'Windows'+last_seen:>'now-7d'. Leave unset to match everything.
limitintegernonullMaximum records to return. CrowdStrike documents a maximum of 1000 for this endpoint; larger values are reduced to it.
sortstringnonullSort expression, in the form property.asc or property.desc.

[CrowdStrike Falcon] Get the Zero Trust Assessment audit report for one customer ID (CID) - the tenant-wide rollup of assessment coverage and scoring rather than per-host detail. It takes no host IDs. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

Agent Invocation

ToolPlanAccessSummary
falcon_get_agent_invocation_v3FreeRead-onlyRetrieves the list of of messages that are resulted from the specified invocation.
falcon_invoke_agent_version_external_v1ProDestructiveInvoke a specific Agentic Studio agent version by agent ID and version ID with the supplied input and return its completion response.
falcon_invoke_published_agent_external_v1ProDestructiveInvoke a published Agentic Studio agent by ID with the supplied input and return its completion response.

[CrowdStrike Falcon] Retrieves the list of of messages that are resulted from the specified invocation. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Read tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
idstringyesRequired. Value for the Falcon id parameter.

[CrowdStrike Falcon] Invoke a specific Agentic Studio agent version by agent ID and version ID with the supplied input and return its completion response. The agent runs live and can call whichever Falcon tools that version was configured with, so the blast radius is that agent tool set rather than this call alone. Supply bodyJson as a JSON object matching the Falcon request body for this operation. THIS CHANGES A LIVE CUSTOMER ENVIRONMENT and requires explicit confirmation before use. Returns the raw Falcon envelope: meta, resources and errors. The errors array can be populated even on a successful call when part of a batch fails, so check it as well as the records in resources. A 403 means this API client was created without the Write tick on this service collection — scopes are fixed when the key is made, so the key must be re-issued in the Falcon console.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body for this Falcon operation.

[CrowdStrike Falcon] Invoke a published Agentic Studio agent by ID wi