Skip to main content
Connector guides

Connect CrowdStrike Falcon

CrowdStrike Falcon is an endpoint detection and response platform. A lightweight sensor on each machine reports what is happening on it, Falcon decides what is a threat, and your analysts work the…

Written By Christopher Scaminaci

Last updated 6 days ago

CrowdStrike Falcon is an endpoint detection and response platform. A lightweight sensor on each machine reports what is happening on it, Falcon decides what is a threat, and your analysts work the resulting alerts. Around that core it also covers cloud posture, containers and Kubernetes, identity protection, vulnerability and exposure management, and Real Time Response — a live remote shell into a managed endpoint. StackJack talks to Falcon through its documented REST API.

Connecting CrowdStrike Falcon to StackJack gives your AI assistant a family of falcon_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. This is the second-largest connector StackJack ships, so the list below is what the tools are for rather than a roster. With them, your AI can:

  • Work the alert queue — search alerts, read the full detection detail behind each one, and pull the aggregate counts that tell you whether today is unusual
  • Report on the fleet — which machines have the sensor, which are stale or unhealthy, what version each one runs, and which policies actually apply to which group
  • Answer "are we exposed to this?" — vulnerability findings per host, exposed assets Falcon discovered on your behalf, misconfiguration findings, and zero trust assessment scores
  • Read threat intelligence — indicator, actor and report lookups, and the sandbox verdict for a file already submitted
  • Audit cloud and containers — cloud posture findings across AWS, Azure, Google Cloud and OCI, container image vulnerabilities, and Kubernetes cluster inventory
  • Review your own configuration — prevention and sensor update policies, exclusions, firewall rules, custom detection rules, users and their roles
  • Contain and remediate (on Pro plans) — network-isolate a compromised machine and lift that containment again, move hosts between groups, and act on quarantined files
  • Change protection (on Pro plans) — edit prevention, sensor update, response, device control and firewall policies, and manage the exclusions that tell the sensor what to ignore
  • Run Real Time Response (on Pro plans) — open a live session to an endpoint and run commands on it
  • Administer the platform (on Pro plans) — manage users, roles, API clients, installation tokens, and, for MSSPs, the customer groups behind Flight Control

How StackJack authenticates to CrowdStrike Falcon

Falcon uses an API client: a Client ID and a Client Secret that you create in the Falcon console. StackJack exchanges them for a short-lived access token, keeps that token fresh, and gets a new one automatically when it expires. There is no consent screen, nothing to reauthorize on a schedule, and no per-user sign-in — the connection acts as the API client you create, not as you.

Choose your cloud region first

This is the one decision to get right before anything else, and it is the single most common cause of a failed first connection.

CrowdStrike runs several independent clouds, and your account lives in exactly one of them. StackJack has no way to discover which — CrowdStrike does not publish one, and asking the wrong cloud does not produce a helpful answer. Credentials sent to the wrong region are rejected in a way that looks identical to a wrong secret. So a region mistake reads as a credential problem, and the natural response is to go and rotate a perfectly good key, which does not help.

For that reason StackJack refuses to guess. The region is a required choice on the connector form, and it starts empty rather than pre-selected. If you do not know yours, the address bar of your Falcon console shows it, and CrowdStrike support can confirm it.

Scopes are fixed when you create the key

Falcon API clients carry permissions per service area, with separate Read and Write ticks for each, and those are chosen when the client is created and cannot be changed afterward. Adding a scope later means issuing a new API client and re-entering the credentials in StackJack.

This is worth a few minutes of thought up front, because it is the most common source of confusion after setup. A key that is missing a scope is not broken — it works perfectly for everything it does cover, and refuses everything else. If your AI reports that Falcon refused one particular area while the rest of the connector works normally, that is a missing tick and not a fault.

Grant Read broadly across the areas you want visibility into, and Write only where you actually want StackJack to make changes. Withholding Write is a genuine safety boundary, and it costs you nothing on the reading side.

Steps

  1. Sign in to the Falcon console as an administrator and open the API clients area under support and resources.
  2. Create an API client. Give it a name that identifies StackJack, so it is obvious later what the key is for.
  3. Choose its scopes. At minimum, tick Read on Hosts — StackJack uses that to test the connection. Then add Read for every area you want your AI to see, and Write only where you want it to act.
  4. Copy the Client ID and Client Secret immediately. Falcon shows the secret exactly once. If you lose it you must create a new client.
  5. Note your cloud region, as above.
  6. Enter all three in StackJack. Open Connectors, choose CrowdStrike Falcon, and enter the Client ID, the Client Secret, and your region.
  7. Run a Test Connection to confirm StackJack can reach Falcon.

If you are an MSSP using Flight Control

If your API client is a parent account that reaches customer accounts through Flight Control, there is one extra field: the customer's CID. Leave it empty and the connection works against your own parent account.

One StackJack connection covers one Falcon customer. If you manage several customers through Flight Control, add a separate connection for each, with that customer's CID. This is deliberate — it means a tool call can never quietly act on the wrong company, because the customer is fixed by the connection rather than chosen per request.

To add one: open Connectors → CrowdStrike Falcon → Add connection, name it after the customer, and enter that customer's CID. Run falcon_query_children on your parent connection to list the child CIDs first. Your AI then names the customer on each call, or you pin an endpoint to one. See Several connections of one connector.

What to know before your AI uses this connector

Some tools reach a live machine

Falcon is not only a reporting system, and several tools take real action on a real endpoint:

  • Containment isolates a machine from the network. It is the correct response to a compromise and it is also disruptive: a contained machine stops talking to everything except Falcon. Lifting containment is a separate tool.
  • Real Time Response is a remote shell. Opening a session dispatches a live channel to the endpoint, and the administrator variants run commands on it. Every Real Time Response tool is treated as an action that changes a customer environment, including the ones whose names sound like bookkeeping — opening a session and keeping it alive both reach the machine.
  • Scans and detonations dispatch work. On-demand scans, network scans and sandbox submissions run against live systems and consume your CrowdStrike quota.
  • Host deletion is permanent.

All of these require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.

Some tools change protection itself

Editing a prevention policy, adding an exclusion, or changing a firewall rule group changes what the sensor does on every machine in scope. Turning a protection off, or excluding a path, deliberately blinds the sensor — which is sometimes exactly right and is never routine. StackJack marks these as destructive for that reason, including the partial edits, and the same applies to suppression rules in cloud security: a suppressed finding disappears from the console and from every report.

Reordering rule precedence counts too. It changes which rule wins without changing any rule.

Reading is safe, and there is a lot of it

Roughly three in five tools only read. Searching, reporting, listing, and pulling detail are all available on the Free tier and none of them change anything. Your AI can investigate an incident end to end — alert, host, policy, vulnerabilities, related detections — without touching a single tool marked destructive. Those reads still return your customers' detection and vulnerability detail, so grant them deliberately.

A successful response can still contain failures

This is specific to Falcon and worth knowing, because it can mislead a person as easily as an assistant. When you ask about several items at once, Falcon can succeed at some and fail at others and report the whole call as successful, listing the failures in a separate part of the response. StackJack passes Falcon's response through exactly as received, so nothing is hidden — but "the call succeeded" and "everything you asked for worked" are different statements here. If a bulk result looks short, the explanation is usually in that part of the response.

Finding things, then reading them

Many Falcon searches return matching identifiers rather than records, and a second tool turns those identifiers into detail. Your AI handles this on its own; the reason to know is that a search reporting matches while showing no detail is normal and not an error.

Searches use CrowdStrike's own filter language, which your AI writes for you.

Plans and limits

Read tools are available on the Free tier. Everything that writes, contains, remediates, runs a command or changes a policy is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated CrowdStrike Falcon tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Falcon limits how fast you can call it, and StackJack paces requests and backs off automatically if you are throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. Falcon also caps how deep you can page into a large result: past roughly ten thousand records a search must be narrowed rather than paged further. Your AI will say so if it reaches that point.

Troubleshooting

"CrowdStrike rejected the credentials" — check the region before you touch the key. A correct Client ID and Secret sent to the wrong cloud fails exactly like a wrong secret, and this is the most common first-connection problem. If the region is right, confirm the Client ID and Secret were copied completely, and remember that Falcon shows the secret only once — if it was not captured at creation, create a new API client.

Falcon accepted the key but refused one particular area — the API client is missing a scope. Scopes are fixed when the client is created, so this cannot be granted after the fact: create a new API client with the ticks you need and re-enter the credentials. The connection test will still pass, because it only needs Read on Hosts.

A Flight Control connection is reading the wrong company — check the customer CID on the connection. Empty means your own parent account, which is a legitimate setting and looks identical to a correctly configured one until you read the data.

A search returns matches but no records — that is the normal two-step pattern described above, not a failure.

A bulk operation reports success but did less than expected — read the failures listed in the response. Falcon reports partial batch failures inside an otherwise successful call.

A large report stops partway with a message about paging depth — Falcon limits how far into a result set you can page. Narrow the search, usually by date range, rather than trying to page further.

CrowdStrike Falcon tools

falcon_ · 1409 tools · Free 845 · Pro 564

Certificate Based Exclusions

ToolWhat it does
falcon_cb_exclusions_create_v1
Pro · Destructive
Create new Certificate Based Exclusions.
falcon_cb_exclusions_delete_v1
Pro · Destructive
Delete the exclusions by id.
falcon_cb_exclusions_get_v1
Free · Read-only
Find all exclusion IDs matching the query with filter.
falcon_cb_exclusions_query_v1
Free · Read-only
Search for cert-based exclusions.
falcon_cb_exclusions_update_v1
Pro · Destructive
Updates existing Certificate Based Exclusions.
falcon_certificates_get_v1
Free · Read-only
Retrieves certificate signing information for a file.

Content Update Policies

ToolWhat it does
falcon_create_content_update_policies
Pro · Write
Create Content Update Policies by specifying details about the policy to create.
falcon_delete_content_update_policies
Pro · Destructive
Delete a set of Content Update Policies by specifying their IDs.
falcon_get_content_update_policies
Free · Read-only
Retrieve a set of Content Update Policies by specifying their IDs.
falcon_perform_content_update_policies_action
Pro · Destructive
Perform the specified action on the Content Update Policies specified in the request.
falcon_query_combined_content_update_policies
Free · Read-only
Search for Content Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_content_update_policy_members
Free · Read-only
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_content_update_policies
Free · Read-only
Search for Content Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_content_update_policy_members
Free · Read-only
Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_pinnable_content_versions
Free · Read-only
Search for content versions available for pinning given the category.
falcon_set_content_update_policies_precedence
Pro · Destructive
Sets the precedence of Content Update Policies based on the order of IDs specified in the request.
falcon_update_content_update_policies
Pro · Destructive
Update Content Update Policies by specifying the ID of the policy and details to update.

Deployments

ToolWhat it does
falcon_combined_release_notes_v1
Free · Read-only
Queries for release-notes resources and returns details.
falcon_combined_releases_v1_mixin0
Free · Read-only
Queries for releases resources and returns details.
falcon_get_deployments_external_v1
Free · Read-only
Get deployment resources by ids.
falcon_get_entity_i_ds_by_query_post
Free · Read-only
returns the release notes for the IDs in the request.
falcon_get_entity_i_ds_by_query_postv2
Free · Read-only
returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format.
falcon_query_release_notes_v1
Free · Read-only
Queries for release-notes resources and returns ids.

Device Content

ToolWhat it does
falcon_entities_states_v1
Free · Read-only
Retrieve the host content state for a number of ids between 1 and 100. Discover IDs with falcon_queries_states_v1. Returns the raw Falcon envelope: meta, resources and errors.
falcon_queries_states_v1
Free · Read-only
Query for the content state of the host.

Device Control Policies

ToolWhat it does
falcon_create_device_control_policies
Pro · Write
Create Device Control Policies by specifying details about the policy to create.
falcon_delete_device_control_policies
Pro · Destructive
Delete a set of Device Control Policies by specifying their IDs.
falcon_get_default_device_control_policies
Free · Read-only
Retrieve the configuration for a Default Device Control Policy.
falcon_get_default_device_control_settings
Free · Read-only
Get default device control settings (USB and Bluetooth).
falcon_get_device_control_policies
Free · Read-only
Retrieve a set of Device Control Policies by specifying their IDs.
falcon_get_device_control_policies_v2
Free · Read-only
Get device control policies for the given filter criteria.
falcon_patch_device_control_policies_classes_v1
Pro · Destructive
Weakens or changes which USB and Bluetooth device classes this policy blocks, for every host in its scope.
falcon_patch_device_control_policies_v2
Pro · Destructive
Weakens or changes USB and Bluetooth enforcement for every host in this device control policy's scope.
falcon_perform_device_control_policies_action
Pro · Destructive
Perform the specified action on the Device Control Policies specified in the request.
falcon_post_device_control_policies_v2
Pro · Write
Create/clone a device control policy (USB and Bluetooth).
falcon_query_combined_device_control_policies
Free · Read-only
Search for Device Control Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_device_control_policy_members
Free · Read-only
Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
falcon_query_device_control_policies
Free · Read-only
Search for Device Control Policies in your environment by providing an FQL filter and paging details.
falcon_query_device_control_policy_members
Free · Read-only
Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details.
falcon_set_device_control_policies_precedence
Pro · Destructive
Sets the precedence of Device Control Policies based on the order of IDs specified in the request.
falcon_update_default_device_control_policies
Pro · Destructive
Update the configuration for a Default Device Control Policy.
falcon_update_default_device_control_settings
Pro · Destructive
Update the configuration for Default Device Control Settings.
falcon_update_device_control_policies
Pro · Destructive
Update Device Control Policies by specifying the ID of the policy and details to update.

Firewall Management

ToolWhat it does
falcon_aggregate_events
Free · Read-only
Aggregate events for customer.
falcon_aggregate_policy_rules
Free · Read-only
Aggregate rules within a policy for customer.
falcon_aggregate_rule_groups
Free · Read-only
Aggregate rule groups for customer.
falcon_aggregate_rules
Free · Read-only
Aggregate rules for customer.
falcon_create_network_locations
Pro · Write
Create new network locations provided, and return the ID.
falcon_create_rule_group
Pro · Write
Create new rule group on a platform for a customer with a name and description, and return the ID.
falcon_create_rule_group_validation
Pro · Write
Validates the request of creating a new rule group on a platform for a customer with a name and description.
falcon_delete_network_locations
Pro · Destructive
Delete network location entities by ID.
falcon_firewall_delete_rule_groups
Pro · Destructive
Delete rule group entities by ID.
falcon_firewall_get_rule_groups
Free · Read-only
Get rule group entities by ID.
falcon_firewall_get_rules
Free · Read-only
Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string).
falcon_firewall_query_events
Free · Read-only
Find all event IDs matching the query with filter.
falcon_firewall_query_rule_groups
Free · Read-only
Find all rule group IDs matching the query with filter.
falcon_firewall_query_rules
Free · Read-only
Find all rule IDs matching the query with filter.
falcon_get_events
Free · Read-only
Get events entities by ID and optionally version.
falcon_get_firewall_fields
Free · Read-only
Get the firewall field specifications by ID.
falcon_get_network_locations
Free · Read-only
Get a summary of network locations entities by ID.
falcon_get_network_locations_details
Free · Read-only
Get network locations entities by ID.
falcon_get_platforms
Free · Read-only
Get platforms by ID, e.g., windows or mac or droid.
falcon_get_policy_containers
Free · Read-only
Get policy container entities by policy ID.
falcon_query_firewall_fields
Free · Read-only
Get the firewall field specification IDs for the provided platform.
falcon_query_network_locations
Free · Read-only
Get a list of network location IDs.
falcon_query_platforms
Free · Read-only
Get the list of platform names.
falcon_query_policy_rules
Free · Read-only
Find all firewall rule IDs matching the query with filter, and return them in precedence order.
falcon_update_network_locations
Pro · Write
Updates the network locations provided, and return the ID.
falcon_update_network_locations_metadata
Pro · Write
Updates the network locations metadata such as polling_intervals for the cid.
falcon_update_network_locations_precedence
Pro · Destructive
Updates the network locations precedence according to the list of ids provided.
falcon_update_policy_container
Pro · Destructive
Update an identified policy container, including local logging functionality.
falcon_update_rule_group
Pro · Destructive
Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules.
falcon_update_rule_group_validation
Pro · Write
Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules.
falcon_upsert_network_locations
Pro · Destructive
Updates the network locations provided, and return the ID.
falcon_validate_filepath_pattern
Pro · Write
Validates that the test pattern matches the executable filepath glob pattern.

Firewall Policies

ToolWhat it does
falcon_create_firewall_policies
Pro · Write
Create Firewall Policies by specifying details about the policy to create.
falcon_delete_firewall_policies
Pro · Destructive
Delete a set of Firewall Policies by specifying their IDs.
falcon_get_firewall_policies
Free · Read-only
Retrieve a set of Firewall Policies by specifying their IDs.
falcon_perform_firewall_policies_action
Pro · Destructive
Perform the specified action on the Firewall Policies specified in the request.
falcon_query_combined_firewall_policies
Free · Read-only
Search for Firewall Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_firewall_policy_members
Free · Read-only
Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
falcon_query_firewall_policies
Free · Read-only
Search for Firewall Policies in your environment by providing an FQL filter and paging details.
falcon_query_firewall_policy_members
Free · Read-only
Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details.
falcon_set_firewall_policies_precedence
Pro · Destructive
Sets the precedence of Firewall Policies based on the order of IDs specified in the request.
falcon_update_firewall_policies
Pro · Destructive
Update Firewall Policies by specifying the ID of the policy and details to update.

Host Groups

ToolWhat it does
falcon_create_host_groups
Pro · Write
Create Host Groups by specifying details about the group to create.
falcon_delete_host_groups
Pro · Destructive
Delete a set of Host Groups by specifying their IDs.
falcon_get_host_groups
Free · Read-only
Retrieve a set of Host Groups by specifying their IDs.
falcon_perform_group_action
Pro · Destructive
Perform the specified action on the Host Groups specified in the request.
falcon_query_combined_group_members
Free · Read-only
Search for members of a Host Group in your environment by providing an FQL filter and paging details.
falcon_query_combined_host_groups
Free · Read-only
Search for Host Groups in your environment by providing an FQL filter and paging details.
falcon_query_group_members
Free · Read-only
Search for members of a Host Group in your environment by providing an FQL filter and paging details.
falcon_query_host_groups
Free · Read-only
Search for Host Groups in your environment by providing an FQL filter and paging details.
falcon_update_host_groups
Pro · Destructive
Edits a host group in place.

Host Migration

ToolWhat it does
falcon_create_migration_v1
Pro · Destructive
Create a device migration job.
falcon_get_host_migration_i_ds_v1
Free · Read-only
Query host migration IDs.
falcon_get_host_migrations_v1
Free · Read-only
Get host migration details.
falcon_get_migration_destinations_v1
Free · Read-only
Get destinations for a migration.
falcon_get_migration_i_ds_v1
Free · Read-only
Query migration jobs.
falcon_get_migrations_v1
Free · Read-only
Get migration job details.
falcon_host_migration_aggregates_v1
Free · Read-only
Get host migration aggregates as specified via json in request body.
falcon_host_migrations_actions_v1
Pro · Destructive
Perform an action on host migrations.
falcon_migration_aggregates_v1
Free · Read-only
Get migration aggregates as specified via json in request body.
falcon_migrations_actions_v1
Pro · Destructive
Perform an action on a migration job.

Hosts

ToolWhat it does
falcon_combined_devices_by_filter
Free · Read-only
Search for hosts in your environment by platform, hostname, IP, and other criteria.
falcon_combined_hidden_devices_by_filter
Free · Read-only
Search for hidden hosts in your environment by platform, hostname, IP, and other criteria.
falcon_devices_actions_delete_v1
Pro · Destructive
Permanently delete hosts from the system.
falcon_entities_perform_action
Pro · Destructive
Performs the specified action on the provided group IDs.
falcon_get_device_details
Free · Read-only
Get details on one or more hosts by providing host IDs in a POST body.
falcon_get_device_details_v1
Free · Read-only
Get details on one or more hosts by providing agent IDs (AID).
falcon_get_device_details_v2
Free · Read-only
Get details on one or more hosts by providing host IDs as a query parameter.
falcon_get_online_state_v1
Free · Read-only
Get the online status for one or more hosts by specifying each host’s unique ID.
falcon_perform_action_v2
Pro · Destructive
Take various actions on the hosts in your environment.
falcon_post_device_details_v2
Free · Read-only
Get details on one or more hosts by providing host IDs in a POST body.
falcon_query_device_login_history
Free · Read-only
Retrieve details about recent login sessions for a set of devices.
falcon_query_device_login_history_v2
Free · Read-only
Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline.
falcon_query_devices_by_filter
Free · Read-only
Search for hosts in your environment by platform, hostname, IP, and other criteria.
falcon_query_devices_by_filter_scroll
Free · Read-only
Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit).
falcon_query_get_network_address_history_v1
Free · Read-only
Retrieve history of IP and MAC addresses of devices.
falcon_query_hidden_devices
Free · Read-only
Retrieve hidden hosts that match the provided filter criteria.
falcon_update_device_tags
Pro · Destructive
Append or remove one or more Falcon Grouping Tags on one or more hosts.

Installation Tokens

ToolWhat it does
falcon_audit_events_query
Free · Read-only
Search for audit events by providing an FQL filter and paging details.
falcon_audit_events_read
Free · Read-only
Gets the details of one or more audit events by id.
falcon_customer_settings_read
Free · Read-only
Check current installation token settings.
falcon_customer_settings_update
Pro · Destructive
Update installation token settings.
falcon_tokens_create
Pro · Destructive
Creates a token.
falcon_tokens_delete
Pro · Destructive
Deletes a token immediately.
falcon_tokens_query
Free · Read-only
Search for tokens by providing an FQL filter and paging details.
falcon_tokens_read
Free · Read-only
Gets the details of one or more tokens by id.
falcon_tokens_update
Pro · Destructive
Updates one or more tokens.

IOA Exclusions

ToolWhat it does
falcon_create_ioa_exclusions_v1
Pro · Destructive
Create the IOA exclusions.
falcon_delete_ioa_exclusions_v1
Pro · Destructive
Delete the IOA exclusions by id.
falcon_get_ioa_exclusions_v1
Free · Read-only
Get a set of IOA Exclusions by specifying their IDs.
falcon_query_ioa_exclusions_v1
Free · Read-only
Search for IOA exclusions.
falcon_ss_ioa_exclusions_aggregates_v2
Free · Read-only
Get Self Service IOA Exclusion aggregates as specified via json in the request body.
falcon_ss_ioa_exclusions_create_v2
Pro · Destructive
Create new Self Service IOA Exclusions.
falcon_ss_ioa_exclusions_delete_v2
Pro · Destructive
Delete the Self Service IOA Exclusions rule by id.
falcon_ss_ioa_exclusions_get_reports_v2
Pro · Destructive
Create a report of Self Service IOA Exclusions scoped by the given filters.
falcon_ss_ioa_exclusions_get_v2
Free · Read-only
Get the Self Service IOA Exclusions rules by id.
falcon_ss_ioa_exclusions_matched_rule_v2
Free · Read-only
Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent.
falcon_ss_ioa_exclusions_new_rules_v2
Free · Read-only
Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent.
falcon_ss_ioa_exclusions_search_v2
Free · Read-only
Search for Self Service IOA Exclusions.
falcon_ss_ioa_exclusions_update_v2
Pro · Destructive
Update the Self Service IOA Exclusions rule by id.
falcon_update_ioa_exclusions_v1
Pro · Destructive
Update the IOA exclusions.

ML Exclusions

ToolWhat it does
falcon_create_ml_exclusions_v1
Pro · Destructive
Create the ML exclusions.
falcon_delete_ml_exclusions_v1
Pro · Destructive
Delete the ML exclusions by id.
falcon_exclusions_aggregates_v2
Free · Read-only
Get exclusion aggregates as specified via json in request body.
falcon_exclusions_create_v2
Pro · Destructive
Create the exclusions, with ancestor fields.
falcon_exclusions_delete_v2
Pro · Destructive
Delete the exclusions by id, with ancestor fields.
falcon_exclusions_get_all_v2
Free · Read-only
Get all exclusions.
falcon_exclusions_get_reports_v2
Pro · Destructive
Create a report of ML exclusions scoped by the given filters.
falcon_exclusions_get_v2
Free · Read-only
Get the exclusions by id, with ancestor fields.
falcon_exclusions_perform_action_v2
Pro · Destructive
Actions used to manipulate the content of exclusions, with ancestor fields.
falcon_exclusions_sdmf_query_v1
Pro · Destructive
Executes an SDMF data frame query against exclusion entities.
falcon_exclusions_search_v2
Free · Read-only
Search for exclusions, with ancestor fields.
falcon_exclusions_update_v2
Pro · Destructive
Update the exclusions by id, with ancestor fields.
falcon_get_ml_exclusions_v1
Free · Read-only
Get a set of ML Exclusions by specifying their IDs.
falcon_query_ml_exclusions_v1
Free · Read-only
Search for ML exclusions.
falcon_update_ml_exclusions_v1
Pro · Destructive
Update the ML exclusions.

Mobile Enrollment

ToolWhat it does
falcon_request_device_enrollment_v3
Pro · Write
Trigger on-boarding process for a mobile device.
falcon_request_device_enrollment_v4
Pro · Write
Trigger on-boarding process for a mobile device.

Prevention Policies

ToolWhat it does
falcon_create_prevention_policies
Pro · Write
Create Prevention Policies by specifying details about the policy to create.
falcon_delete_prevention_policies
Pro · Destructive
Delete a set of Prevention Policies by specifying their IDs.
falcon_get_prevention_policies
Free · Read-only
Retrieve a set of Prevention Policies by specifying their IDs.
falcon_perform_prevention_policies_action
Pro · Destructive
Perform the specified action on the Prevention Policies specified in the request.
falcon_query_combined_prevention_policies
Free · Read-only
Search for Prevention Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_prevention_policy_members
Free · Read-only
Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
falcon_query_prevention_policies
Free · Read-only
Search for Prevention Policies in your environment by providing an FQL filter and paging details.
falcon_query_prevention_policy_members
Free · Read-only
Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details.
falcon_set_prevention_policies_precedence
Pro · Destructive
Sets the precedence of Prevention Policies based on the order of IDs specified in the request.
falcon_update_prevention_policies
Pro · Destructive
Update Prevention Policies by specifying the ID of the policy and details to update.

Profile Groups

ToolWhat it does
falcon_create_group_v1_mixin0
Pro · Write
Create a new profile group.
falcon_delete_groups_v1
Pro · Destructive
Delete profile groups by IDs.
falcon_get_group_users_v1
Free · Read-only
Get a list of groups with users that belong to them.
falcon_get_groups_v1_mixin0
Free · Read-only
Get profile groups by IDs with full details.
falcon_get_user_groups_v1
Free · Read-only
Get a list of users with the groups that they belong to.
falcon_group_actions_v1_mixin0
Pro · Destructive
Perform actions on profile groups (add/remove roles, user groups, FGA objects).
falcon_group_users_actions_v1_mixin0
Pro · Destructive
Add or remove users from profile groups.
falcon_query_groups_v1_mixin0
Free · Read-only
Query profile group IDs with FQL filtering, pagination, and sorting.
falcon_update_group_v1_mixin0
Pro · Write
Update profile group metadata (name, description).

Response Policies

ToolWhat it does
falcon_create_rt_response_policies
Pro · Write
Create Response Policies by specifying details about the policy to create.
falcon_delete_rt_response_policies
Pro · Destructive
Delete a set of Response Policies by specifying their IDs.
falcon_get_rt_response_policies
Free · Read-only
Retrieve a set of Response Policies by specifying their IDs.
falcon_perform_rt_response_policies_action
Pro · Destructive
Perform the specified action on the Response Policies specified in the request.
falcon_query_combined_rt_response_policies
Free · Read-only
Search for Response Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_rt_response_policy_members
Free · Read-only
Search for members of a Response policy in your environment by providing an FQL filter and paging details.
falcon_query_rt_response_policies
Free · Read-only
Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details.
falcon_query_rt_response_policy_members
Free · Read-only
Search for members of a Response policy in your environment by providing an FQL filter and paging details.
falcon_set_rt_response_policies_precedence
Pro · Destructive
Sets the precedence of Response Policies based on the order of IDs specified in the request.
falcon_update_rt_response_policies
Pro · Destructive
Update Response Policies by specifying the ID of the policy and details to update.

Sensor Download

ToolWhat it does
falcon_get_sensor_installers_by_query
Free · Read-only
Get sensor installer IDs by provided query.
falcon_get_sensor_installers_by_query_v2
Free · Read-only
Get sensor installer IDs by provided query.
falcon_get_sensor_installers_by_query_v3
Free · Read-only
Get sensor installer IDs by provided query.
falcon_get_sensor_installers_ccid_by_query
Free · Read-only
Get CCID to use with sensor installers.
falcon_get_sensor_installers_entities
Free · Read-only
Get sensor installer details by provided SHA256 IDs.
falcon_get_sensor_installers_entities_v2
Free · Read-only
Get sensor installer details by provided SHA256 IDs.
falcon_get_sensor_installers_entities_v3
Free · Read-only
Get sensor installer details by provided SHA256 IDs.

Sensor Update Policy

ToolWhat it does
falcon_create_sensor_update_policies
Pro · Write
Create Sensor Update Policies by specifying details about the policy to create.
falcon_create_sensor_update_policies_v2
Pro · Write
Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection.
falcon_delete_sensor_update_policies
Pro · Destructive
Delete a set of Sensor Update Policies by specifying their IDs.
falcon_get_sensor_update_policies
Free · Read-only
Retrieve a set of Sensor Update Policies by specifying their IDs.
falcon_get_sensor_update_policies_v2
Free · Read-only
Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs.
falcon_increment_uninstall_token
Pro · Destructive
Increments a bulk maintenance token.
falcon_perform_sensor_update_policies_action
Pro · Destructive
Perform the specified action on the Sensor Update Policies specified in the request.
falcon_query_combined_sensor_update_builds
Free · Read-only
Retrieve available builds for use with Sensor Update Policies.
falcon_query_combined_sensor_update_kernels
Free · Read-only
Retrieve kernel compatibility info for Sensor Update Builds.
falcon_query_combined_sensor_update_policies
Free · Read-only
Search for Sensor Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_combined_sensor_update_policies_v2
Free · Read-only
Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details.
falcon_query_combined_sensor_update_policy_members
Free · Read-only
Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
falcon_query_sensor_update_kernels_distinct
Free · Read-only
Retrieve kernel compatibility info for Sensor Update Builds.
falcon_query_sensor_update_policies
Free · Read-only
Search for Sensor Update Policies in your environment by providing an FQL filter and paging details.
falcon_query_sensor_update_policy_members
Free · Read-only
Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details.
falcon_reveal_uninstall_token
Pro · Write
Reveals an uninstall token for a specific device.
falcon_set_sensor_update_policies_precedence
Pro · Destructive
Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request.
falcon_update_sensor_update_policies
Pro · Destructive
Update Sensor Update Policies by specifying the ID of the policy and details to update.
falcon_update_sensor_update_policies_v2
Pro · Destructive
Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection.

Sensor Usage

ToolWhat it does
falcon_get_sensor_usage_hourly
Free · Read-only
Fetches hourly average.
falcon_get_sensor_usage_weekly
Free · Read-only
Fetches weekly average.

Sensor Visibility Exclusions

ToolWhat it does
falcon_create_sv_exclusions_v1
Pro · Destructive
Create the sensor visibility exclusions.
falcon_delete_sensor_visibility_exclusions_v1
Pro · Destructive
Delete the sensor visibility exclusions by id.
falcon_get_sensor_visibility_exclusions_v1
Free · Read-only
Get a set of Sensor Visibility Exclusions by specifying their IDs.
falcon_query_sensor_visibility_exclusions_v1
Free · Read-only
Search for sensor visibility exclusions.
falcon_update_sensor_visibility_exclusions_v1
Pro · Destructive
Update the sensor visibility exclusions.

Alerts

ToolWhat it does
falcon_get_queries_alerts_v2
Free · Read-only
Search for alert IDs matching an FQL filter.
falcon_patch_entities_alerts_v1
Pro · Destructive
Apply an action to one or more detections by detection ID.
falcon_patch_entities_alerts_v3
Pro · Destructive
Apply an action to one or more alerts by composite ID.
falcon_post_aggregates_alerts_v2
Free · Read-only
Retrieves aggregate values for Alerts across all CIDs.
falcon_post_combined_alerts_v1
Free · Read-only
Search alerts with an FQL filter and get the full records back in one call.
falcon_post_entities_alerts_v2
Free · Read-only
Read full alert records for the composite IDs you supply.

Hunting

ToolWhat it does
falcon_aggregate_hunting_guides
Free · Read-only
Aggregate Hunting Guides.
falcon_aggregate_intelligence_queries
Free · Read-only
Aggregate intelligence queries.
falcon_get_archive_export
Free · Read-only
Creates an Archive Export.
falcon_get_hunting_guides
Free · Read-only
Retrieves a list of Hunting Guides.
falcon_get_intelligence_queries
Free · Read-only
Retrieves the details of a list of Intelligence queries IDs.
falcon_search_hunting_guides
Free · Read-only
Search for Hunting Guides that match the provided conditions.
falcon_search_intelligence_queries
Free · Read-only
Search for a list of intelligence queries IDs that match the provided conditions.

Correlation Rules

ToolWhat it does
falcon_aggregates_rule_versions_post_v1
Free · Read-only
Get rules aggregates as specified via json in the request body.
falcon_combined_rules_get_v1
Free · Read-only
Search correlation rules with a query and filter and get the full records back in one call, instead of searching for IDs and reading them separately.
falcon_combined_rules_get_v2
Free · Read-only
Find all rules matching the query and filter.
falcon_entities_latest_rules_get_v1
Free · Read-only
Retrieve latest rule versions by rule IDs.
falcon_entities_rule_versions_delete_v1
Pro · Destructive
Delete correlation rule versions by ID.
falcon_entities_rule_versions_export_post_v1
Pro · Write
Export correlation rule versions.
falcon_entities_rule_versions_import_post_v1
Pro · Destructive
Import correlation rule versions from an exported payload.
falcon_entities_rule_versions_publish_patch_v1
Pro · Destructive
Publish an existing correlation rule version.
falcon_entities_rules_delete_v1
Pro · Destructive
Delete correlation rules by ID.
falcon_entities_rules_get_v1
Free · Read-only
Read full correlation rule records for the IDs you supply.
falcon_entities_rules_get_v2
Free · Read-only
Retrieve rule versions by IDs.
falcon_entities_rules_patch_v1
Pro · Destructive
Update existing correlation rules.
falcon_entities_rules_post_v1
Pro · Write
Create a correlation rule.
falcon_entities_templates_get_v1_mixin0
Free · Read-only
Retrieve rule templates by IDs.
falcon_entities_templates_rules_post_v1
Pro · Write
Create a correlation rule from a CrowdStrike rule template.
falcon_queries_rules_get_v1
Free · Read-only
Search for correlation rule IDs matching a query and filter.
falcon_queries_rules_get_v2
Free · Read-only
Find all rule version IDs matching the query and filter.
falcon_queries_templates_get_v1_mixin0
Free · Read-only
Search rule template IDs matching the filter.

Correlation Rules Admin

ToolWhat it does
falcon_entities_rules_ownership_put_v1
Pro · Destructive
Change the owner of an existing correlation rule.
falcon_entities_rules_ownership_put_v2
Pro · Destructive
Bulk change the owner of existing correlation rules.

Custom Indicators of Attack

ToolWhat it does
falcon_create_rule
Pro · Destructive
Create a rule inside a Custom IOA rule group and return it.
falcon_create_rule_group_mixin0
Pro · Write
Create a Custom IOA rule group for a platform, with a name and an optional description, and return it.
falcon_delete_rule_groups_mixin0
Pro · Destructive
Delete Custom IOA rule groups by ID.
falcon_get_patterns
Free · Read-only
Get pattern severities by ID.
falcon_get_platforms_mixin0
Free · Read-only
Get platforms by ID.
falcon_get_rule_groups_mixin0
Free · Read-only
Read full Custom IOA rule groups by ID, including the rules they contain.
falcon_get_rule_types
Free · Read-only
Get rule types by ID.
falcon_get_rules_get
Free · Read-only
Get rules by ID and optionally with cid and/or version in the following format: `[cid:]ID[:version]`.
falcon_get_rules_mixin0
Free · Read-only
Read full Custom IOA rules by ID, optionally with a customer ID and a version, in the form [cid:]ID[:version].
falcon_ioa_delete_rules
Pro · Destructive
Delete rules from a Custom IOA rule group by ID.
falcon_ioa_update_rules
Pro · Destructive
Update rules inside a Custom IOA rule group and return them.
falcon_query_patterns
Free · Read-only
Get all pattern severity IDs.
falcon_query_platforms_mixin0
Free · Read-only
Get all platform IDs.
falcon_query_rule_groups_full
Free · Read-only
Find all rule groups matching the query with optional filter.
falcon_query_rule_groups_mixin0
Free · Read-only
Search for Custom IOA rule group IDs matching a query, with an optional filter.
falcon_query_rule_types
Free · Read-only
Get all rule type IDs.
falcon_query_rules_mixin0
Free · Read-only
Search for Custom IOA rule IDs matching a query, with an optional filter.
falcon_update_rule_group_mixin0
Pro · Destructive
Update a Custom IOA rule group.
falcon_update_rules_v2
Pro · Destructive
Update the name, description, enabled flag or field values of individual rules in a Custom IOA rule group and return them.
falcon_validate
Pro · Write
Validate Custom IOA rule field values and, when a test string is supplied, report whether it matches.

Falcon Identity

ToolWhat it does
falcon_delete_third_party_passkey_registry
Pro · Destructive
Delete third party passkey registries.
falcon_get_third_party_passkey_registry
Free · Read-only
Fetches third party passkey registries.
falcon_query_third_party_passkey_registry
Free · Read-only
Query third party passkey registries.
falcon_update_third_party_passkey_registry
Pro · Destructive
Update third party passkey registries.

Falcon Sandbox

ToolWhat it does
falcon_delete_report
Pro · Destructive
Delete a sandbox report by report ID.
falcon_delete_sample_v2
Pro · Destructive
Remove a sample from the collection, including the file, its metadata and its submissions.
falcon_get_memory_dump
Free · Read-only
Read the content of a sandbox memory dump.
falcon_get_memory_dump_extracted_strings
Free · Read-only
Get extracted strings from a memory dump.
falcon_get_memory_dump_hex_dump
Free · Read-only
Get hex view of a memory dump.
falcon_get_reports
Free · Read-only
Read a full sandbox report by report ID, including the behavioral analysis.
falcon_get_submissions
Free · Read-only
Check the status of a sandbox analysis.
falcon_get_summary_reports
Free · Read-only
Read the short summary form of a sandbox report by report ID.
falcon_query_reports
Free · Read-only
Search for sandbox report IDs with an FQL filter.
falcon_query_sample_v1
Free · Read-only
Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200. This returns matching IDs only, not the records themselves.
falcon_query_submissions
Free · Read-only
Find submission IDs for uploaded files by providing an FQL filter and paging details.
falcon_submit
Pro · Destructive
Submit an uploaded file or a URL to Falcon Sandbox for analysis.
falcon_upload_sample_v2
Pro · Destructive
Upload a file to Falcon Sandbox for analysis.

Identity Protection

ToolWhat it does
falcon_delete_policy_rules
Pro · Destructive
Delete Identity Protection policy rules.
falcon_get_policy_rules
Free · Read-only
Get policy rules.
falcon_get_policy_rules_query
Free · Read-only
Query policy rule IDs.
falcon_get_sensor_aggregates
Free · Read-only
Get sensor aggregates as specified via json in request body.
falcon_get_sensor_details
Free · Read-only
Read details for one or more Identity Protection sensors by device ID, supplied in the request body.
falcon_post_graphql
Pro · Destructive
Run a GraphQL operation against the Identity Protection API.
falcon_post_policy_rules
Pro · Destructive
Create an Identity Protection policy rule.
falcon_query_sensors_by_filter
Free · Read-only
Search for Identity Protection sensors in the customer environment by hostname, address and other criteria, and return their IDs.

Intel

ToolWhat it does
falcon_cao_incidents_aggregates_v1
Free · Read-only
Perform statistical aggregations over incident data.
falcon_cao_incidents_entities_v1
Free · Read-only
Retrieve full details for one or more adversary incidents by their IDs.
falcon_cao_incidents_queries_v1
Free · Read-only
Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs.
falcon_get_intel_actor_entities
Free · Read-only
Read full CrowdStrike Intelligence adversary profiles for the actor IDs you supply.
falcon_get_intel_indicator_entities
Free · Read-only
Read full CrowdStrike Intelligence indicator records for the indicator IDs you supply.
falcon_get_intel_report_entities
Free · Read-only
Read full CrowdStrike Intelligence reports for the report IDs you supply.
falcon_get_intel_report_pdf
Free · Read-only
Read the PDF attachment of a CrowdStrike Intelligence report.
falcon_get_intel_rule_entities
Free · Read-only
Retrieve details for rule sets for the specified ids.
falcon_get_intel_rule_file
Free · Read-only
Download an earlier CrowdStrike Intelligence rule set.
falcon_get_latest_intel_rule_file
Free · Read-only
Download the latest CrowdStrike Intelligence rule set.
falcon_get_malware_entities
Free · Read-only
Get malware entities for specified ids.
falcon_get_malware_mitre_report
Free · Read-only
Export Mitre ATT&CK information for a given malware family.
falcon_get_mitre_report
Free · Read-only
Export Mitre ATT&CK information for a given actor.
falcon_intel_get_vulnerabilities
Free · Read-only
Get vulnerabilities.
falcon_intel_query_vulnerabilities
Free · Read-only
Get vulnerabilities IDs.
falcon_post_mitre_attacks
Free · Read-only
Retrieves report and observable IDs associated with the given actor and attacks.
falcon_query_intel_actor_entities
Free · Read-only
Search CrowdStrike Intelligence adversaries with an FQL filter and get the full profiles back in one call.
falcon_query_intel_actor_ids
Free · Read-only
Search CrowdStrike Intelligence for adversary IDs matching an FQL filter.
falcon_query_intel_indicator_entities
Free · Read-only
Search CrowdStrike Intelligence indicators with an FQL filter and get the full records back in one call.
falcon_query_intel_indicator_ids
Free · Read-only
Search CrowdStrike Intelligence for indicator IDs matching an FQL filter.
falcon_query_intel_report_entities
Free · Read-only
Search CrowdStrike Intelligence reports with an FQL filter and get the full records back in one call.
falcon_query_intel_report_ids
Free · Read-only
Search CrowdStrike Intelligence for report IDs matching an FQL filter.
falcon_query_intel_rule_ids
Free · Read-only
Search for rule IDs that match provided filter criteria.
falcon_query_malware
Free · Read-only
Get malware family names that match provided FQL filters.
falcon_query_malware_entities
Free · Read-only
Get malware entities that match provided FQL filters.
falcon_query_mitre_attacks
Free · Read-only
Gets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071. This returns matching IDs only, not the records themselves — pass the IDs to falcon_post_mitre_attacks to read the detail.
falcon_query_mitre_attacks_for_malware
Free · Read-only
Gets MITRE tactics and techniques for the given malware.

Intelligence Feeds

ToolWhat it does
falcon_list_feed_types
Free · Read-only
Lists the accessible feed types for a given customer.
falcon_query_feed_archives
Free · Read-only
Queries the accessible feed types for a customer.

Intelligence Indicator Graph

ToolWhat it does
falcon_lookup_indicators
Free · Read-only
Look up indicator graph records by their value, such as a hash, domain or address, rather than by ID.
falcon_search_indicators
Free · Read-only
Search the CrowdStrike indicator graph with an FQL filter.

Indicators of Compromise

ToolWhat it does
falcon_action_get_v1
Free · Read-only
Get Actions by ids.
falcon_action_query_v1
Free · Read-only
Query Actions.
falcon_get_indicators_report
Free · Read-only
Launch an indicators report creation job.
falcon_indicator_aggregate_v1
Free · Read-only
Get Indicators aggregates as specified via json in the request body.
falcon_indicator_combined_v1
Free · Read-only
Search custom indicators of compromise with an FQL filter and get the full records back in one call, instead of searching for IDs and reading them separately.
falcon_indicator_create_v1
Pro · Destructive
Create custom indicators of compromise.
falcon_indicator_delete_v1
Pro · Destructive
Delete custom indicators of compromise by ID.
falcon_indicator_get_device_count_v1
Free · Read-only
Get the number of devices the indicator has run on.
falcon_indicator_get_devices_ran_on_v1
Free · Read-only
Get the IDs of devices the indicator has run on.
falcon_indicator_get_processes_ran_on_v1
Free · Read-only
Get the number of processes the indicator has run on.
falcon_indicator_get_v1
Free · Read-only
Read full custom indicator of compromise records for the IDs you supply.
falcon_indicator_sdmf_query_v1
Pro · Write
Run a structured data frame query over custom indicators of compromise.
falcon_indicator_search_v1
Free · Read-only
Search for custom indicator of compromise IDs with an FQL filter.
falcon_indicator_update_v1
Pro · Destructive
Update custom indicators of compromise by ID.
falcon_ioc_type_query_v1
Free · Read-only
Query IOC Types.
falcon_platform_query_v1
Free · Read-only
Query Platforms.
falcon_severity_query_v1
Free · Read-only
Query Severities.
ToolWhat it does
falcon_devices_count
Free · Read-only
Number of hosts in your customer account that have observed a given custom IOC.
falcon_devices_ran_on
Free · Read-only
Find the hosts that have observed a given custom indicator of compromise, and return their device IDs.
falcon_entities_processes
Free · Read-only
For the provided ProcessID retrieve the process details.
falcon_processes_ran_on
Free · Read-only
Find the processes associated with a given custom indicator of compromise on a specific host, and return their process IDs.

MalQuery

ToolWhat it does
falcon_get_mal_query_entities_samples_fetch_v1
Free · Read-only
Fetch the zip archive of MalQuery samples prepared by an earlier request, protected with the password infected.
falcon_get_mal_query_metadata_v1
Free · Read-only
Retrieve indexed files metadata by their hash.
falcon_get_mal_query_quotas_v1
Free · Read-only
Get information about search and download quotas in your environment.
falcon_get_mal_query_request_v1
Free · Read-only
Check the status and results of an asynchronous request, such as hunt or exact-search.
falcon_post_mal_query_exact_search_v1
Free · Read-only
Search MalQuery for an exact combination of hex patterns and strings, matching samples at byte level.
falcon_post_mal_query_fuzzy_search_v1
Free · Read-only
Search MalQuery quickly for a combination of hex patterns and strings, matching samples at byte level.
falcon_post_mal_query_hunt_v1
Free · Read-only
Schedule a YARA rule to run across the MalQuery corpus.

On-Demand Scans

ToolWhat it does
falcon_aggregate_query_scan_host_metadata
Free · Read-only
Get aggregates on ODS scan-hosts data.
falcon_aggregate_scans
Free · Read-only
Get aggregates on ODS scan data.
falcon_aggregate_scheduled_scans
Free · Read-only
Get aggregates on ODS scheduled-scan data.
falcon_cancel_scans
Pro · Destructive
Cancel running on-demand scans by scan ID.
falcon_create_scan
Pro · Destructive
Create an on-demand scan and start or schedule it for the hosts named in the request.
falcon_delete_scheduled_scans
Pro · Destructive
Delete scheduled on-demand scans by ID.
falcon_get_malicious_files_by_ids
Free · Read-only
Get malicious files by ids.
falcon_get_scan_host_metadata_by_ids
Free · Read-only
Get scan hosts by ids.
falcon_get_scans_by_scan_ids
Free · Read-only
Read full on-demand scan records for the scan IDs you supply.
falcon_get_scans_by_scan_ids_v2
Free · Read-only
Get Scans by IDs.
falcon_get_scheduled_scans_by_scan_ids
Free · Read-only
Get ScheduledScans by IDs.
falcon_query_malicious_files
Free · Read-only
Query malicious files.
falcon_query_scan_host_metadata
Free · Read-only
Query scan hosts.
falcon_query_scans
Free · Read-only
Search for on-demand scan IDs with an FQL filter.
falcon_query_scheduled_scans
Free · Read-only
Query ScheduledScans.
falcon_scans_report
Pro · Write
Launch a job that builds a report of on-demand scan results.
falcon_schedule_scan
Pro · Destructive
Create a scheduled on-demand scan for the hosts named in the request.

Quarantine

ToolWhat it does
falcon_action_update_count
Free · Read-only
Returns count of potentially affected quarantined files for each action.
falcon_get_aggregate_files
Free · Read-only
Get quarantine file aggregates as specified via json in request body.
falcon_get_quarantine_files
Free · Read-only
Read quarantined file metadata for the IDs you supply.
falcon_query_quarantine_files
Free · Read-only
Search for quarantined file IDs with an FQL filter.
falcon_update_qf_by_query
Pro · Destructive
Apply an action to every quarantined file matching an FQL filter.
falcon_update_quarantined_detects_by_ids
Pro · Destructive
Apply an action to quarantined files by quarantine file ID.

Quick Scan

ToolWhat it does
falcon_get_scans_aggregates
Free · Read-only
Get scans aggregations as specified via json in request body.
falcon_qscan_get_scans
Free · Read-only
Check the status of a volume scan.
falcon_query_submissions_mixin0
Free · Read-only
Find IDs for submitted scans by providing an FQL filter and paging details.
falcon_scan_samples
Pro · Destructive
Submit a volume of uploaded files for machine-learning scanning.

Quick Scan Pro

ToolWhat it does
falcon_delete_file
Pro · Destructive
Delete a QuickScan Pro file by its SHA256. The stored sample is removed, and any scan that referenced it loses its source file.
falcon_delete_scan_result
Pro · Destructive
Delete the result of a QuickScan Pro scan.
falcon_get_scan_result
Free · Read-only
Gets the result of an QuickScan Pro scan.
falcon_launch_scan
Pro · Destructive
Start a QuickScan Pro scan of a file already uploaded through the QuickScan Pro file endpoint.
falcon_query_scan_results
Free · Read-only
FQL query specifying the filter parameters.
falcon_upload_file_mixin0_mixin94
Pro · Destructive
Upload a file for QuickScan Pro analysis.
falcon_upload_file_quick_scan_pro
Pro · Destructive
Upload a file for QuickScan Pro analysis, as multipart form data or as an octet stream.

Recon

ToolWhat it does
falcon_aggregate_notifications_exposed_data_records_v1
Free · Read-only
Get notification exposed data record aggregates as specified via JSON in request body.
falcon_aggregate_notifications_v1
Free · Read-only
Get notification aggregates as specified via JSON in request body.
falcon_create_actions_v1
Pro · Write
Create actions for a monitoring rule.
falcon_create_export_jobs_v1
Pro · Write
Launch an asynchronous recon export job and return its job ID.
falcon_create_rules_v1
Pro · Write
Create monitoring rules.
falcon_delete_action_v1
Pro · Destructive
Delete an action from a monitoring rule by action ID.
falcon_delete_export_jobs_v1
Pro · Destructive
Delete recon export jobs and the files they produced, by job ID.
falcon_delete_notifications_v1
Pro · Destructive
Delete recon notifications by ID.
falcon_delete_rules_v1
Pro · Destructive
Delete monitoring rules by ID.
falcon_get_actions_v1
Free · Read-only
Get actions based on their IDs.
falcon_get_export_jobs_v1
Free · Read-only
Get the status of export jobs based on their IDs.
falcon_get_file_content_for_export_jobs_v1
Free · Read-only
Download the file produced by a recon export job.
falcon_get_notifications_detailed_translated_v1
Free · Read-only
Get detailed notifications based on their IDs.
falcon_get_notifications_detailed_v1
Free · Read-only
Read recon notifications for the IDs you supply, including the raw intelligence content behind each one.
falcon_get_notifications_exposed_data_records_v1
Free · Read-only
Get notifications exposed data records based on their IDs.
falcon_get_notifications_translated_v1
Free · Read-only
Get notifications based on their IDs.
falcon_get_notifications_v1
Free · Read-only
Read recon notifications for the IDs you supply.
falcon_get_rules_v1
Free · Read-only
Read full monitoring rules for the IDs you supply.
falcon_preview_rule_v1
Free · Read-only
Preview rules notification count and distribution.
falcon_query_actions_v1
Free · Read-only
Query actions based on provided criteria.
falcon_query_notifications_exposed_data_records_v1
Free · Read-only
Query notifications exposed data records based on provided criteria.
falcon_query_notifications_v1
Free · Read-only
Search for recon notification IDs matching the criteria you provide.
falcon_query_rules_v1
Free · Read-only
Search for monitoring rule IDs matching the criteria you provide.
falcon_update_action_v1
Pro · Write
Update an action on a monitoring rule.
falcon_update_notifications_v1
Pro · Destructive
Update the status or the assignee of recon notifications, in bulk.
falcon_update_rules_v1
Pro · Destructive
Update monitoring rules.

Sample Uploads

ToolWhat it does
falcon_archive_delete_v1
Pro · Destructive
Delete an archive that was uploaded earlier.
falcon_archive_get_v1
Free · Read-only
Retrieves the archives upload operation statuses.
falcon_archive_list_v1
Free · Read-only
Retrieves the archives files in chunks.
falcon_archive_upload_v1
Pro · Destructive
Upload an archive and extract its file list.
falcon_archive_upload_v2
Pro · Destructive
Upload an archive and extract its file list.
falcon_delete_sample_v3
Pro · Destructive
Remove a sample from the collection, including the file, its metadata and its submissions.
falcon_extraction_create_v1
Pro · Write
Extract the files from an archive that was already uploaded and copy them into internal storage so they can be analyzed.
falcon_extraction_get_v1
Free · Read-only
Retrieves the files extraction operation statuses.
falcon_extraction_list_v1
Free · Read-only
Retrieves the files extractions in chunks.
falcon_upload_sample_v3
Pro · Destructive
Upload a file for cloud analysis.

Tailored Intelligence

ToolWhat it does
falcon_get_events_body
Free · Read-only
Get event body for the provided event ID.
falcon_get_events_entities
Free · Read-only
Read tailored intelligence events for the IDs you supply.
falcon_get_rules_entities
Free · Read-only
Read tailored intelligence rules for the IDs you supply.
falcon_tailored_intelligence_query_events
Free · Read-only
Search for tailored intelligence event IDs matching an FQL filter.
falcon_tailored_intelligence_query_rules
Free · Read-only
Search for tailored intelligence rule IDs matching an FQL filter.

Threatgraph

ToolWhat it does
falcon_combined_edges_get
Free · Read-only
Read the Threat Graph edges leaving a vertex.
falcon_combined_ran_on_get
Free · Read-only
Look up where an indicator such as a hash, domain name or address has been observed running in the customer environment.
falcon_combined_summary_get
Free · Read-only
Read the Threat Graph summary for a vertex ID.
falcon_entities_vertices_get
Free · Read-only
Retrieve metadata for a ThreatGraph vertex by id.
falcon_entities_vertices_getv2
Free · Read-only
Retrieve metadata for a given vertex ID.
falcon_queries_edgetypes_get
Free · Read-only
Show all available edge types.

Configuration Assessment

ToolWhat it does
falcon_get_combined_assessments_query
Free · Read-only
Search Falcon configuration assessment findings by FQL filter and return the matching host findings in one call.
falcon_get_rule_details
Free · Read-only
Get the details of one or more configuration assessment rules by rule ID.

Configuration Assessment Evaluation Logic

ToolWhat it does
falcon_get_evaluation_logic_mixin0
Free · Read-only
Get the evaluation logic behind one or more configuration assessment findings, by finding ID.

Data Protection Configuration

ToolWhat it does
falcon_entities_classification_delete_v2
Pro · Destructive
Delete Falcon Data Protection classifications by ID.
falcon_entities_classification_get_v2
Free · Read-only
Get Falcon Data Protection classification records by ID.
falcon_entities_classification_patch_v2
Pro · Write
Update a Falcon Data Protection classification.
falcon_entities_classification_post_v2
Pro · Write
Create a Falcon Data Protection classification, labeling data by what it contains so policies can act on the label.
falcon_entities_cloud_application_create
Pro · Write
Create a Falcon Data Protection cloud application - a SaaS destination policies can allow or block.
falcon_entities_cloud_application_delete
Pro · Destructive
Delete Falcon Data Protection cloud applications by ID.
falcon_entities_cloud_application_get
Free · Read-only
Get Falcon Data Protection cloud application records by ID.
falcon_entities_cloud_application_patch
Pro · Write
Update a Falcon Data Protection cloud application.
falcon_entities_content_pattern_create
Pro · Write
Create a Falcon Data Protection content pattern - the keywords or expressions a classification uses to recognize data.
falcon_entities_content_pattern_delete
Pro · Destructive
Delete Falcon Data Protection content patterns by ID.
falcon_entities_content_pattern_get
Free · Read-only
Get Falcon Data Protection content pattern records by ID.
falcon_entities_content_pattern_patch
Pro · Write
Update a Falcon Data Protection content pattern.
falcon_entities_enterprise_account_create
Pro · Write
Create a Falcon Data Protection enterprise account, identifying the customer own tenant inside a cloud application so policies can tell corporate destinations from personal ones.
falcon_entities_enterprise_account_delete
Pro · Destructive
Delete Falcon Data Protection enterprise accounts by ID.
falcon_entities_enterprise_account_get
Free · Read-only
Get Falcon Data Protection enterprise account records by ID.
falcon_entities_enterprise_account_patch
Pro · Write
Update a Falcon Data Protection enterprise account.
falcon_entities_file_type_get
Free · Read-only
Get Falcon Data Protection file type records by ID.
falcon_entities_local_application_create
Pro · Write
Create a Falcon Data Protection local application - an endpoint application policies can allow or block from handling classified data.
falcon_entities_local_application_delete
Pro · Destructive
Delete Falcon Data Protection local applications by ID.
falcon_entities_local_application_get
Free · Read-only
Get Falcon Data Protection local application records by ID.
falcon_entities_local_application_group_create
Pro · Write
Create a Falcon Data Protection local application group, bundling applications so one policy rule can name many.
falcon_entities_local_application_group_delete
Pro · Destructive
Delete Falcon Data Protection local application groups by ID.
falcon_entities_local_application_group_get
Free · Read-only
Get Falcon Data Protection local application group records by ID.
falcon_entities_local_application_group_patch
Pro · Write
Update a Falcon Data Protection local application group.
falcon_entities_local_application_patch
Pro · Write
Update a Falcon Data Protection local application.
falcon_entities_policy_delete_v2
Pro · Destructive
Delete Falcon Data Protection policies by ID.
falcon_entities_policy_get_v2
Free · Read-only
Get Falcon Data Protection policy records by ID.
falcon_entities_policy_patch_v2
Pro · Destructive
Weakens or changes the Data Protection enforcement applied to every host in this policy's scope.
falcon_entities_policy_post_v2
Pro · Write
Create a Falcon Data Protection policy.
falcon_entities_policy_precedence_post_v1
Pro · Destructive
Set the precedence order of Falcon Data Protection policies.
falcon_entities_sensitivity_label_create_v2
Pro · Write
Create a Falcon Data Protection sensitivity label, mirroring a label from the customer own labeling system.
falcon_entities_sensitivity_label_delete_v2
Pro · Destructive
Delete Falcon Data Protection sensitivity labels by ID.
falcon_entities_sensitivity_label_get_v2
Free · Read-only
Get Falcon Data Protection sensitivity label records by ID.
falcon_entities_web_location_create_v2
Pro · Write
Create a Falcon Data Protection web location - a destination policies can allow or block.
falcon_entities_web_location_delete_v2
Pro · Destructive
Delete Falcon Data Protection web locations by ID.
falcon_entities_web_location_get_v2
Free · Read-only
Get Falcon Data Protection web location records by ID.
falcon_entities_web_location_group_create
Pro · Write
Create a Falcon Data Protection web location group, bundling destinations so one policy rule can name many.
falcon_entities_web_location_group_delete
Pro · Destructive
Delete Falcon Data Protection web location groups by ID.
falcon_entities_web_location_group_get
Free · Read-only
Get Falcon Data Protection web location group records by ID.
falcon_entities_web_location_group_patch
Pro · Write
Update a Falcon Data Protection web location group.
falcon_entities_web_location_patch_v2
Pro · Write
Update a Falcon Data Protection web location.
falcon_queries_classification_get_v2
Free · Read-only
Search Falcon Data Protection classifications by FQL filter, returning classification IDs only.
falcon_queries_cloud_application_get_v2
Free · Read-only
Search Falcon Data Protection cloud applications by FQL filter, returning application IDs only.
falcon_queries_content_pattern_get_v2
Free · Read-only
Search Falcon Data Protection content patterns by FQL filter, returning content pattern IDs only.
falcon_queries_enterprise_account_get_v2
Free · Read-only
Search Falcon Data Protection enterprise accounts by FQL filter, returning account IDs only.
falcon_queries_file_type_get_v2
Free · Read-only
Search Falcon Data Protection file types by FQL filter, returning file type IDs only.
falcon_queries_local_application_get
Free · Read-only
Search Falcon Data Protection local applications by FQL filter, returning application IDs only.
falcon_queries_local_application_group_get
Free · Read-only
Search Falcon Data Protection local application groups by FQL filter, returning group IDs only.
falcon_queries_policy_get_v2
Free · Read-only
Search Falcon Data Protection policies by FQL filter, returning policy IDs only.
falcon_queries_sensitivity_label_get_v2
Free · Read-only
Search Falcon Data Protection sensitivity labels by FQL filter, returning label IDs only.
falcon_queries_web_location_get_v2
Free · Read-only
Search Falcon Data Protection web locations by FQL filter, returning web location IDs only.
falcon_queries_web_location_group_get
Free · Read-only
Search Falcon Data Protection web location groups by FQL filter, returning group IDs only.

Discover

ToolWhat it does
falcon_combined_applications
Free · Read-only
Search Falcon Discover for installed applications by FQL filter and return the full application records in one call, rather than the IDs falcon_query_applications returns.
falcon_combined_hosts
Free · Read-only
Search Falcon Discover for assets by FQL filter and return the full asset records in one call, rather than the IDs falcon_query_hosts returns.
falcon_get_accounts
Free · Read-only
Get full Falcon Discover account records for one or more account IDs, including the account type, the privilege level and the host the account was seen on.
falcon_get_applications
Free · Read-only
Get full Falcon Discover application records for one or more application IDs, including the vendor, the version and the assets the application is installed on.
falcon_get_hosts
Free · Read-only
Get full Falcon Discover asset records for one or more asset IDs, including the operating system, network addresses, owner and first and last seen times.
falcon_get_iot_hosts
Free · Read-only
Get full Falcon Discover IoT and operational-technology asset records for one or more asset IDs.
falcon_get_logins
Free · Read-only
Get full Falcon Discover login records for one or more login IDs, including the account, the host and the login time.
falcon_query_accounts
Free · Read-only
Search Falcon Discover for user accounts by FQL filter, returning account IDs only.
falcon_query_applications
Free · Read-only
Search Falcon Discover for installed applications by FQL filter, returning application IDs only.
falcon_query_hosts
Free · Read-only
Search Falcon Discover for assets by FQL filter, returning asset IDs only.
falcon_query_iot_hosts
Free · Read-only
Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only.
falcon_query_iot_hosts_v2
Free · Read-only
Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only.
falcon_query_logins
Free · Read-only
Search Falcon Discover for login events by FQL filter, returning login IDs only.

Exposure Management

ToolWhat it does
falcon_aggregate_external_assets
Free · Read-only
Return counts and groupings over your external attack surface rather than individual assets, for example assets by country, by service or by criticality.
falcon_blob_preview_external_assets
Free · Read-only
Fetch a preview of a binary blob attached to an external asset, such as a captured screenshot or service banner.
falcon_combined_ecosystem_subsidiaries
Free · Read-only
Search your mapped subsidiaries by FQL filter and return the full records in one call, rather than the IDs falcon_query_ecosystem_subsidiaries returns.
falcon_delete_external_assets
Pro · Destructive
Remove external assets from your external attack surface inventory by ID.
falcon_get_ecosystem_subsidiaries
Free · Read-only
Get full records for one or more ecosystem subsidiary IDs.
falcon_get_external_assets
Free · Read-only
Get full external asset records for one or more external asset IDs, including the hostname, resolved addresses, open ports, discovered services and how CrowdStrike attributed the asset to you.
falcon_patch_external_assets
Pro · Write
Update fields on existing external assets, such as criticality or ownership.
falcon_post_external_assets_inventory_v1
Pro · Write
Add external assets to the scanning inventory so CrowdStrike begins attributing and monitoring them.
falcon_query_ecosystem_subsidiaries
Free · Read-only
Search your mapped subsidiaries and related organizations by FQL filter, returning subsidiary IDs only.
falcon_query_external_assets
Free · Read-only
Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only.
falcon_query_external_assets_v2
Free · Read-only
Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only.

Falcon Complete Dashboard

ToolWhat it does
falcon_aggregate_alerts
Free · Read-only
Return counts and groupings over endpoint protection alerts for the Falcon Complete dashboard, rather than the alert records themselves.
falcon_aggregate_allow_list
Free · Read-only
Return counts and groupings over Falcon Complete allowlist tickets, rather than the tickets themselves.
falcon_aggregate_block_list
Free · Read-only
Return counts and groupings over Falcon Complete blocklist tickets, rather than the tickets themselves.
falcon_aggregate_device_count_collection
Free · Read-only
Return host and device counts for the Falcon Complete dashboard, grouped by the criteria in the request body.
falcon_aggregate_escalations
Free · Read-only
Return counts and groupings over Falcon Complete escalation tickets, rather than the tickets themselves.
falcon_aggregate_fc_incidents
Free · Read-only
DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incident aggregates.
falcon_aggregate_prevention_policy
Free · Read-only
Return counts and groupings over prevention policy assignment for the Falcon Complete dashboard.
falcon_aggregate_remediations
Free · Read-only
Return counts and groupings over Falcon Complete remediation tickets, rather than the tickets themselves.
falcon_aggregate_sensor_update_policy
Free · Read-only
Return counts and groupings over sensor update policy assignment for the Falcon Complete dashboard.
falcon_aggregate_support_issues
Free · Read-only
Return counts and groupings over Falcon Complete support issue tickets, rather than the tickets themselves.
falcon_aggregate_total_device_counts
Free · Read-only
Return the total host and device count for the Falcon Complete dashboard.
falcon_get_device_count_collection_queries_by_filter
Free · Read-only
Search Falcon Complete device count collections by FQL filter, returning collection IDs only.
falcon_query_alert_ids_by_filter
Free · Read-only
Search Falcon Complete endpoint protection alerts by FQL filter, returning alert IDs only.
falcon_query_alert_ids_by_filter_v2
Free · Read-only
Search Falcon Complete endpoint, identity and Next-Gen SIEM alerts by FQL filter, returning alert IDs only.
falcon_query_allow_list_filter
Free · Read-only
Search Falcon Complete allowlist tickets by FQL filter, returning ticket IDs only.
falcon_query_block_list_filter
Free · Read-only
Search Falcon Complete blocklist tickets by FQL filter, returning ticket IDs only.
falcon_query_escalations_filter
Free · Read-only
Search Falcon Complete escalation tickets by FQL filter, returning ticket IDs only.
falcon_query_incident_ids_by_filter
Free · Read-only
DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incidents.
falcon_query_remediations_filter
Free · Read-only
Search Falcon Complete remediation tickets by FQL filter, returning ticket IDs only.

FileVantage

ToolWhat it does
falcon_create_rule_groups
Pro · Write
Create a FileVantage rule group.
falcon_create_rules
Pro · Write
Create a rule inside a FileVantage rule group, naming the paths, file types and actions to watch.
falcon_create_scheduled_exclusions
Pro · Destructive
Blinds FileVantage change detection for the window this exclusion covers.
falcon_delete_policies
Pro · Destructive
Delete FileVantage policies by ID.
falcon_delete_scheduled_exclusions
Pro · Destructive
Delete scheduled exclusions from a FileVantage policy by ID.
falcon_filevantage_create_policies
Pro · Write
Create a FileVantage policy.
falcon_filevantage_delete_rule_groups
Pro · Destructive
Delete FileVantage rule groups by ID.
falcon_filevantage_delete_rules
Pro · Destructive
Delete rules from a FileVantage rule group by ID.
falcon_filevantage_get_rule_groups
Free · Read-only
Get the configuration of one or more FileVantage rule groups by ID, including the ids of the rules inside them.
falcon_filevantage_get_rules
Free · Read-only
Get the configuration of one or more FileVantage rules by ID, within a rule group.
falcon_filevantage_query_rule_groups
Free · Read-only
Search FileVantage rule groups of a given type, returning rule group IDs only.
falcon_filevantage_update_policies
Pro · Write
Update a FileVantage policy.
falcon_filevantage_update_policy_precedence
Pro · Destructive
Set the precedence order of FileVantage policies for a policy type.
falcon_filevantage_update_rules
Pro · Write
Update a rule inside a FileVantage rule group.
falcon_get_actions_mixin0
Free · Read-only
Get the processing results of one or more FileVantage actions by action ID - what a previously started action did and whether it succeeded.
falcon_get_changes
Free · Read-only
Get FileVantage change records for one or more change IDs, including the host, the file or registry path, the action and the actor.
falcon_get_contents
Free · Read-only
Get the file content FileVantage captured for one change ID, where content capture is enabled on the rule that caught it.
falcon_get_policies
Free · Read-only
Get the configuration of one or more FileVantage policies by ID, including the assigned host groups and rule groups.
falcon_get_scheduled_exclusions
Free · Read-only
Get the configuration of one or more scheduled exclusions from a FileVantage policy.
falcon_high_volume_query_changes
Free · Read-only
Search FileVantage changes by FQL filter, returning change IDs only, using the high-volume search that pages past the classic 10,000-record window with an after cursor.
falcon_query_actions_mixin0
Free · Read-only
Search FileVantage actions by FQL filter, returning action IDs only.
falcon_query_changes
Free · Read-only
Search FileVantage changes by FQL filter, returning change IDs only.
falcon_query_policies
Free · Read-only
Search FileVantage policies of a given policy type, returning policy IDs only.
falcon_query_scheduled_exclusions
Free · Read-only
Search the scheduled exclusions inside one FileVantage policy, returning exclusion IDs only.
falcon_signal_changes_external
Pro · Destructive
Initiate FileVantage workflows for the supplied change ids.
falcon_start_actions
Pro · Destructive
Start a FileVantage action against the supplied change ids.
falcon_update_policy_host_groups
Pro · Destructive
Assign or unassign host groups on a FileVantage policy.
falcon_update_policy_rule_groups
Pro · Destructive
Assign or unassign rule groups on a FileVantage policy.
falcon_update_rule_group_precedence
Pro · Destructive
Set the precedence order of the rules inside a FileVantage rule group.
falcon_update_rule_groups
Pro · Write
Update a FileVantage rule group.
falcon_update_scheduled_exclusions
Pro · Destructive
Blinds FileVantage change detection for the window this exclusion covers.

Network Scan Global Configs

ToolWhat it does
falcon_get_global_configs
Free · Read-only
Get the tenant-wide network scan configuration for this customer ID, such as default scan windows and global exclusions.
falcon_update_global_configs
Pro · Write
Update the tenant-wide network scan configuration for this customer ID.

Network Scan Networks

ToolWhat it does
falcon_aggregate_networks
Free · Read-only
Return counts and groupings over network scan targets, rather than the records themselves.
falcon_create_networks
Pro · Write
Create network scan targets - the address ranges a scanner is allowed to scan.
falcon_delete_networks
Pro · Destructive
Delete network scan targets by ID.
falcon_get_networks
Free · Read-only
Get network scan target records by ID, including the address ranges and the zone they belong to.
falcon_query_networks
Free · Read-only
Search network scan targets by FQL filter, returning network IDs only.
falcon_update_networks
Pro · Write
Update network scan targets.

Network Scan Scan Run Reports

ToolWhat it does
falcon_get_scan_run_reports
Free · Read-only
Download the report for a network scan run.

Network Scan Scan Runs

ToolWhat it does
falcon_aggregate_scan_runs
Free · Read-only
Return counts and groupings over network scan runs, rather than the records themselves.
falcon_create_scan_runs
Pro · Destructive
Start a network scan run - one immediate execution of a scan definition.
falcon_get_scan_runs
Free · Read-only
Get network scan run records by ID, including the status, the timing and the findings summary of that execution.
falcon_query_scan_runs
Free · Read-only
Search network scan runs by FQL filter, returning scan run IDs only.
falcon_update_scan_runs
Pro · Write
Update a network scan run in flight, for example to change its state.

Network Scan Scanners

ToolWhat it does
falcon_aggregate_scanners
Free · Read-only
Return counts and groupings over deployed network scanners, rather than the records themselves.
falcon_get_scanners
Free · Read-only
Get network scanner records by ID, including the host running the scanner, its version and its health.
falcon_query_scanners
Free · Read-only
Search deployed network scanners by FQL filter, returning scanner IDs only.
falcon_update_scanners
Pro · Write
Update the configuration of a deployed network scanner.

Network Scan Scans

ToolWhat it does
falcon_aggregate_scans_mixin0
Free · Read-only
Return counts and groupings over network scan definitions, rather than the records themselves.
falcon_create_scans
Pro · Destructive
Create a network scan definition - target networks, template and schedule.
falcon_delete_scans
Pro · Destructive
Delete network scan definitions by ID.
falcon_netscan_get_scans
Free · Read-only
Get network scan definition records by ID, including the target networks, the template and the schedule.
falcon_query_scans_mixin0
Free · Read-only
Search network scan definitions by FQL filter, returning scan IDs only.
falcon_update_scans
Pro · Write
Update a network scan definition.

Network Scan Templates

ToolWhat it does
falcon_create_templates
Pro · Write
Create a reusable network scan template - what to probe and how aggressively.
falcon_delete_templates
Pro · Destructive
Delete network scan templates by ID.
falcon_get_template_configs
Free · Read-only
Get the setting detail behind the network scan templates - the individual probes and options a template turns on.
falcon_get_templates
Free · Read-only
Get network scan template records by ID.
falcon_query_templates
Free · Read-only
Search network scan templates by FQL filter, returning template IDs only.
falcon_update_templates
Pro · Write
Update a network scan template.

Network Scan Zones

ToolWhat it does
falcon_aggregate_zones
Free · Read-only
Return counts and groupings over network scan zones, rather than the records themselves.
falcon_combined_zones
Free · Read-only
Search network scan zones by FQL filter and return the full zone records in one call, rather than the IDs falcon_query_zones returns.
falcon_create_zones
Pro · Write
Create a network scan zone, grouping address ranges with the scanners allowed to reach them.
falcon_delete_zones
Pro · Destructive
Delete network scan zones by ID.
falcon_get_zones
Free · Read-only
Get network scan zone records by ID.
falcon_query_zones
Free · Read-only
Search network scan zones by FQL filter, returning zone IDs only.
falcon_update_zones
Pro · Write
Update a network scan zone.

SaaS Security

ToolWhat it does
falcon_dismiss_affected_entity_v3
Pro · Write
Dismiss one affected entity from a SaaS Security posture check, suppressing that entity from the check results.
falcon_dismiss_security_check_v3
Pro · Write
Dismiss a SaaS Security posture check by ID, suppressing it from the posture view.
falcon_get_activity_monitor_v3
Free · Read-only
Get the SaaS Security activity feed - user and administrator actions recorded in connected SaaS applications.
falcon_get_alerts_v3
Free · Read-only
Get SaaS Security alerts - one alert by ID, or the list.
falcon_get_app_inventory
Free · Read-only
Get the inventory of SaaS applications CrowdStrike discovered in this tenant, sanctioned and unsanctioned.
falcon_get_app_inventory_users
Free · Read-only
Get the users of a discovered SaaS application, including how they signed in and when they were last active.
falcon_get_asset_inventory_v3
Free · Read-only
Get the SaaS Security data inventory - the files and data objects held in connected SaaS applications, with their sensitivity classification.
falcon_get_device_inventory_v3
Free · Read-only
Get the SaaS Security device inventory - the devices seen accessing connected SaaS applications.
falcon_get_integrations_v3
Free · Read-only
Get the SaaS application integrations connected to SaaS Security, with their connection status.
falcon_get_metrics_v3
Free · Read-only
Get the SaaS Security summary metrics - the rollup counters behind the posture dashboard, such as open checks by severity.
falcon_get_security_check_affected_v3
Free · Read-only
Get the accounts, users or resources a SaaS Security posture check flagged.
falcon_get_security_check_compliance_v3
Free · Read-only
Get the compliance framework mappings for SaaS Security posture checks - which control in which standard each check satisfies.
falcon_get_security_checks_v3
Free · Read-only
Get SaaS Security posture checks - one check by ID, or the list of checks.
falcon_get_supported_saas_v3
Free · Read-only
Get the catalog of SaaS applications SaaS Security can connect to.
falcon_get_system_logs_v3
Free · Read-only
Get the SaaS Security system log - the audit trail of SaaS Security own activity, such as connector runs and configuration changes.
falcon_get_system_users_v3
Free · Read-only
Get the SaaS Security system users - the accounts that administer SaaS Security itself, not the users of the connected applications.
falcon_get_user_inventory_v3
Free · Read-only
Get the SaaS Security user inventory - the identities seen across connected SaaS applications, with their roles and privilege level.
falcon_integration_builder_end_transaction_v3
Pro · Write
Close an open custom SaaS Security integration data upload transaction, committing what was uploaded.
falcon_integration_builder_get_status_v3
Free · Read-only
Get the status of a custom SaaS Security integration build, including how far an in-progress data upload transaction has reached.
falcon_integration_builder_reset_v3
Pro · Destructive
Reset a custom SaaS Security integration, discarding its in-progress state and any uploaded data that was not committed.
falcon_integration_builder_upload_v3
Pro · Write
Upload data into an open custom SaaS Security integration transaction.

Spotlight Evaluation Logic

ToolWhat it does
falcon_combined_query_evaluation_logic
Free · Read-only
Search Spotlight evaluation logic by FQL filter and return the full records in one call, rather than the IDs falcon_query_evaluation_logic returns.
falcon_combined_supported_evaluation_ext
Free · Read-only
Search and return the evaluation types Spotlight supports, in one call.
falcon_get_evaluation_logic
Free · Read-only
Get Spotlight evaluation logic records by ID.
falcon_query_evaluation_logic
Free · Read-only
Search Spotlight evaluation logic by FQL filter, returning evaluation logic IDs only.

Spotlight Vulnerabilities

ToolWhat it does
falcon_combined_query_installed_patches
Free · Read-only
DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns installed-patch data for hosts.
falcon_combined_query_vulnerabilities
Free · Read-only
Search Falcon Spotlight for vulnerabilities by FQL filter and return the full vulnerability records in one call, rather than the IDs falcon_spotlight_query_vulnerabilities returns.
falcon_get_remediations
Free · Read-only
Get Spotlight remediation records by ID, first generation.
falcon_get_remediations_v2
Free · Read-only
Get Spotlight remediation records by ID.
falcon_spotlight_get_vulnerabilities
Free · Read-only
Get full Spotlight vulnerability records for one or more vulnerability IDs, including the affected host, the CVE, the severity and the ids of the recommended remediations.
falcon_spotlight_query_vulnerabilities
Free · Read-only
Search Falcon Spotlight for vulnerabilities across your managed hosts by FQL filter, returning vulnerability IDs only.

Spotlight Vulnerability Metadata

ToolWhat it does
falcon_combine_vuln_metadata_ext
Free · Read-only
Search Spotlight vulnerability metadata and return the matching records in one call.

Zero Trust Assessment

ToolWhat it does
falcon_get_assessment_v1
Free · Read-only
Get Zero Trust Assessment scores for specific hosts, by agent ID (AID) and customer ID (CID).
falcon_get_assessments_by_score_v1
Free · Read-only
Find hosts whose Zero Trust Assessment score falls in a range, for one customer ID (CID).
falcon_get_audit_v1
Free · Read-only
Get the Zero Trust Assessment audit report for one customer ID (CID) - the tenant-wide rollup of assessment coverage and scoring rather than per-host detail.

Agent Invocation

ToolWhat it does
falcon_get_agent_invocation_v3
Free · Read-only
Retrieves the list of of messages that are resulted from the specified invocation.
falcon_invoke_agent_version_external_v1
Pro · Destructive
Invoke a specific Agentic Studio agent version by agent ID and version ID with the supplied input and return its completion response.
falcon_invoke_published_agent_external_v1
Pro · Destructive
Invoke a published Agentic Studio agent by ID with the supplied input and return its completion response.

Agent Templates

ToolWhat it does
falcon_entities_agent_templates_v1
Free · Read-only
Retrieve agent template entities for the provided IDs.
falcon_queries_agent_templates_v1
Free · Read-only
Query agent template IDs with pagination.

Agent Versions

ToolWhat it does
falcon_get_agent_versions_v1
Free · Read-only
Retrieve agent version entities for the provided ids.
falcon_query_agent_versions_v1
Free · Read-only
Query agent versions based on the provided filters.

Custom Storage

ToolWhat it does
falcon_delete_object
Pro · Destructive
Delete the specified object from a custom-storage collection.
falcon_delete_versioned_object
Pro · Destructive
Delete the specified object from a versioned custom-storage collection.
falcon_describe_collection
Free · Read-only
Fetch metadata about an existing collection.
falcon_describe_collections
Free · Read-only
Fetch metadata about one or more existing custom-storage collections.
falcon_get_object
Free · Read-only
Get the bytes for the specified object.
falcon_get_object_metadata
Free · Read-only
Get the metadata for the specified object.
falcon_get_schema
Free · Read-only
Get the bytes of the specified schema of the requested collection.
falcon_get_schema_metadata
Free · Read-only
Get the metadata for the specified schema of the requested collection.
falcon_get_versioned_object
Free · Read-only
Get the bytes for the specified object.
falcon_get_versioned_object_metadata
Free · Read-only
Get the metadata for the specified object.
falcon_list_collections
Free · Read-only
List available collection names in alphabetical order.
falcon_list_objects
Free · Read-only
List the object keys in the specified collection in alphabetical order.
falcon_list_objects_by_version
Free · Read-only
List the object keys in the specified collection in alphabetical order.
falcon_list_schemas
Free · Read-only
Get the list of schemas for the requested collection in reverse version order (latest first).
falcon_put_object
Pro · Destructive
Put a new object at the given key in a custom-storage collection, or overwrite the object already at that key.
falcon_put_object_by_version
Pro · Destructive
Put a new object at the given key in a versioned custom-storage collection, or overwrite the object already at that key.
falcon_search_objects
Free · Read-only
Search for objects that match the specified filter criteria (returns metadata, not actual objects).
falcon_search_objects_by_version
Free · Read-only
Search for objects that match the specified filter criteria (returns metadata, not actual objects).

Delivery Settings

ToolWhat it does
falcon_get_delivery_settings
Free · Read-only
Get Delivery Settings.
falcon_post_delivery_settings
Pro · Write
Create Delivery Settings.

Faas Execution

ToolWhat it does
falcon_read_request_body
Free · Read-only
retrieve a large request body, such as a file, that has spilled into object storage.

Foundry Logscale

ToolWhat it does
falcon_create_saved_searches_dynamic_execute_v1
Pro · Write
Execute a dynamic saved search.
falcon_create_saved_searches_execute_v1
Pro · Write
Execute a saved search.
falcon_create_saved_searches_ingest_v1
Pro · Write
Populate a saved search.
falcon_foundry_logscale_create_file_v1
Pro · Write
DECOMMISSIONED: Creates a lookup file.
falcon_foundry_logscale_update_file_v1
Pro · Destructive
DECOMMISSIONED by CrowdStrike: updates a lookup file.
falcon_get_saved_searches_execute_v1
Free · Read-only
Get the results of a saved search.
falcon_ingest_data_async_v1
Pro · Write
Asynchronously ingest data into the application repository.
falcon_ingest_data_v1
Pro · Write
Synchronously ingest data into the application repository.
falcon_list_repos_v1
Free · Read-only
Lists available repositories.
falcon_list_view_v1
Free · Read-only
List available views.

Foundry Lookup Files

ToolWhat it does
falcon_foundry_lookup_files_create_file_v1
Pro · Write
Creates a lookup file within a foundry app.
falcon_foundry_lookup_files_update_file_v1
Pro · Destructive
Updates a lookup file within a Foundry app.

Falcon for IT

ToolWhat it does
falcon_it_automation_cancel_task_execution
Pro · Destructive
Cancel a Falcon for IT task execution.
falcon_it_automation_combined_scheduled_tasks
Free · Read-only
Returns full details of scheduled tasks matching the filter query parameter.
falcon_it_automation_create_policy
Pro · Destructive
Creates a new policy of the specified type.
falcon_it_automation_create_scheduled_task
Pro · Destructive
Creates a scheduled task from the given request.
falcon_it_automation_create_task
Pro · Destructive
Creates a task with details from the given request.
falcon_it_automation_create_task_group
Pro · Destructive
Creates a task group from the given request.
falcon_it_automation_create_user_group
Pro · Destructive
Creates a user group from the given request.
falcon_it_automation_delete_policy
Pro · Destructive
Deletes one or more Falcon for IT policies.
falcon_it_automation_delete_scheduled_tasks
Pro · Destructive
Delete one or more scheduled tasks by providing the scheduled tasks IDs.
falcon_it_automation_delete_task
Pro · Destructive
Deletes tasks for each provided ID.
falcon_it_automation_delete_task_groups
Pro · Destructive
Delete one or more task groups by providing the task group IDs.
falcon_it_automation_delete_user_group
Pro · Destructive
Deletes user groups for each provided ids.
falcon_it_automation_get_associated_tasks
Free · Read-only
Retrieve tasks associated with the provided file id.
falcon_it_automation_get_execution_results
Free · Read-only
Get the task execution results from an async search.
falcon_it_automation_get_execution_results_search_status
Free · Read-only
Get the status of an async task execution results.
falcon_it_automation_get_policies
Free · Read-only
Retrieves the configuration for 1 or more policies.
falcon_it_automation_get_scheduled_tasks
Free · Read-only
Returns scheduled tasks for each provided id.
falcon_it_automation_get_task_execution
Free · Read-only
Get the task execution for the provided task execution IDs.
falcon_it_automation_get_task_execution_host_status
Free · Read-only
Get the status of host executions by providing the execution IDs.
falcon_it_automation_get_task_executions_by_query
Free · Read-only
Returns the list of task executions (and their details) matching the filter query parameter.
falcon_it_automation_get_task_groups
Free · Read-only
Returns task groups for each provided id.
falcon_it_automation_get_task_groups_by_query
Free · Read-only
Returns full details of task groups matching the filter query parameter.
falcon_it_automation_get_tasks
Free · Read-only
Returns tasks for each provided ID.
falcon_it_automation_get_tasks_by_query
Free · Read-only
Returns full details of tasks matching the filter query parameter.
falcon_it_automation_get_user_group
Free · Read-only
Returns user groups for each provided id.
falcon_it_automation_query_policies
Free · Read-only
Returns the list of policy ids matching the filter query parameter.
falcon_it_automation_rerun_task_execution
Pro · Destructive
Rerun the Falcon for IT task execution named in the request.
falcon_it_automation_run_live_query
Pro · Destructive
Starts a new Falcon for IT task execution from the query data in the request and returns the initiated executions.
falcon_it_automation_search_scheduled_tasks
Free · Read-only
Returns the list of scheduled task IDs matching the filter query parameter.
falcon_it_automation_search_task_executions
Free · Read-only
Returns the list of task execution IDs matching the filter query parameter.
falcon_it_automation_search_task_groups
Free · Read-only
Returns the list of task group ids matching the filter query parameter.
falcon_it_automation_search_tasks
Free · Read-only
Returns the list of task IDs matching the filter query parameter.
falcon_it_automation_search_user_group
Free · Read-only
Returns the list of user group ids matching the filter query parameter.
falcon_it_automation_start_execution_results_search
Pro · Destructive
Starts an async task execution results search.
falcon_it_automation_start_task_execution
Pro · Destructive
Starts a new Falcon for IT task execution from an existing task and returns the initiated executions.
falcon_it_automation_update_policies
Pro · Destructive
Updates a new policy of the specified type.
falcon_it_automation_update_policies_precedence
Pro · Destructive
Updates the policy precedence for all Falcon for IT policies on a platform.
falcon_it_automation_update_policy_host_groups
Pro · Destructive
Manage the host groups assigned to a Falcon for IT policy.
falcon_it_automation_update_scheduled_task
Pro · Destructive
Update an existing scheduled task with the supplied info.
falcon_it_automation_update_task
Pro · Destructive
Update a task with details from the given request.
falcon_it_automation_update_task_group
Pro · Destructive
Update a task group for a given id.
falcon_it_automation_update_user_group
Pro · Destructive
Update a user group for a given id.

Knowledge Base Audit Events

ToolWhat it does
falcon_aggregates_knowledge_base_audit_events_v1
Free · Read-only
DECOMMISSIONED: Aggregate knowledge base audit events based on the provided msa criteria.
falcon_combined_knowledge_base_audit_events_v1
Free · Read-only
Get knowledge base audit events with full event details and pagination.
falcon_entities_knowledge_base_audit_events_v1
Free · Read-only
Retrieve knowledge base audit event entities by their IDs.
falcon_queries_knowledge_base_audit_events_v1
Free · Read-only
Query knowledge base audit event IDs with pagination and filtering.

Knowledge Base Files

ToolWhat it does
falcon_entities_knowledge_base_files_create_v1
Pro · Write
Upload a file to a knowledge base.
falcon_entities_knowledge_base_files_delete_v1
Pro · Destructive
Delete a document from an Agentic Studio knowledge base.
falcon_entities_knowledge_base_files_update_v1
Pro · Destructive
Update an existing file in an Agentic Studio knowledge base, optionally its description as well as its content.
falcon_entities_knowledge_base_files_v1
Free · Read-only
Retrieve knowledge base file entities for the provided id.
falcon_queries_knowledge_base_files_v1
Free · Read-only
Query knowledge base files based on the provided filters.

Knowledge Bases

ToolWhat it does
falcon_aggregates_knowledge_bases_v1
Free · Read-only
DECOMMISSIONED: Aggregate knowledge bases based on the provided msa criteria.
falcon_combined_knowledge_bases_v1
Free · Read-only
Search for knowledge bases with filtering and return full entity details in a single response.
falcon_entities_knowledge_bases_create_v1
Pro · Destructive
Create or update an Agentic Studio knowledge base.
falcon_entities_knowledge_bases_update_v1
Pro · Write
Update an existing knowledge base.
falcon_entities_knowledge_bases_v1
Free · Read-only
Retrieve knowledge base entities for the provided id.
falcon_queries_knowledge_bases_v1
Free · Read-only
Query knowledge bases based on the provided filters.

Models

ToolWhat it does
falcon_entities_models_v1
Free · Read-only
Get Model Entities by IDs.
falcon_queries_models_v1
Free · Read-only
Search the models available to Falcon's agentic studio and return their ids.

Real Time Response

ToolWhat it does
falcon_batch_active_responder_cmd
Pro · Destructive
Batch executes a Real Time Response Active Responder command across every host mapped to the given batch ID.
falcon_batch_cmd
Pro · Destructive
Batch executes a Real Time Response read-only command across every host mapped to the given batch ID.
falcon_batch_get_cmd
Pro · Destructive
Batch executes the Real Time Response get command across the hosts mapped to a batch ID to retrieve a file from each of them; poll falcon_batch_get_cmd_status for the results.
falcon_batch_get_cmd_status
Free · Read-only
Retrieves the status of the specified batch get command.
falcon_batch_init_sessions
Pro · Destructive
Batch initialize a Real Time Response session on multiple hosts.
falcon_batch_refresh_sessions
Pro · Destructive
Batch refresh a Real Time Response session on multiple hosts.
falcon_rtr_aggregate_sessions
Free · Read-only
Get aggregates on session data.
falcon_rtr_check_active_responder_command_status
Free · Read-only
Get status of an executed active-responder command on a single host.
falcon_rtr_check_command_status
Free · Read-only
Get status of an executed command on a single host.
falcon_rtr_delete_file
Pro · Destructive
Delete a Real Time Response session file, meaning a file the session get command retrieved.
falcon_rtr_delete_file_v2
Pro · Destructive
Delete a Real Time Response session file, meaning a file the session get command retrieved.
falcon_rtr_delete_queued_session
Pro · Destructive
Delete a queued Real Time Response session command.
falcon_rtr_delete_session
Pro · Destructive
Delete a Real Time Response session.
falcon_rtr_execute_active_responder_command
Pro · Destructive
Execute a Real Time Response Active Responder command on a single host, inside a session that is already open.
falcon_rtr_execute_command
Pro · Destructive
Execute a Real Time Response read-only command on a single host, inside a session that is already open.
falcon_rtr_init_session
Pro · Destructive
Initialize a new Real Time Response session with the RTR cloud against a single host.
falcon_rtr_list_all_sessions
Free · Read-only
Get a list of session_ids.
falcon_rtr_list_files
Free · Read-only
Get a list of files for the specified RTR session.
falcon_rtr_list_files_v2
Free · Read-only
Get a list of files for the specified RTR session.
falcon_rtr_list_queued_sessions
Free · Read-only
Get queued session metadata by session ID.
falcon_rtr_list_sessions
Free · Read-only
Get session metadata by session id.
falcon_rtr_pulse_session
Pro · Destructive
Refresh the Real Time Response session timeout on a single host.

Real Time Response (Admin)

ToolWhat it does
falcon_batch_admin_cmd
Pro · Destructive
Batch executes a Real Time Response Administrator command across every host mapped to the given batch ID.
falcon_rtr_check_admin_command_status
Free · Read-only
Get status of an executed RTR administrator command on a single host.
falcon_rtr_create_put_files
Pro · Destructive
Upload a new put-file for the Real Time Response put command.
falcon_rtr_create_put_files_v2
Pro · Destructive
Upload a new put-file for the Real Time Response put command.
falcon_rtr_create_scripts
Pro · Destructive
Upload a new custom script for the Real Time Response runscript command.
falcon_rtr_create_scripts_v2
Pro · Destructive
Upload a new custom script for the Real Time Response runscript command.
falcon_rtr_delete_put_files
Pro · Destructive
Delete a Real Time Response put-file by ID, one file per call.
falcon_rtr_delete_scripts
Pro · Destructive
Delete a Real Time Response custom script by ID, one script per call.
falcon_rtr_execute_admin_command
Pro · Destructive
Execute a Real Time Response Administrator command on a single host, inside a session that is already open.
falcon_rtr_get_falcon_scripts
Free · Read-only
Get Falcon scripts with metadata and content of script.
falcon_rtr_get_put_file_contents
Free · Read-only
Get RTR put file contents for a given file ID.
falcon_rtr_get_put_files
Free · Read-only
Get put-files based on the ID's given.
falcon_rtr_get_put_files_v2
Free · Read-only
Get put-files based on the ID's given.
falcon_rtr_get_scripts
Free · Read-only
Get custom-scripts based on the ID's given.
falcon_rtr_get_scripts_v2
Free · Read-only
Get custom-scripts based on the ID's given.
falcon_rtr_list_falcon_scripts
Free · Read-only
Get a list of Falcon script IDs available to the user to run.
falcon_rtr_list_put_files
Free · Read-only
Get a list of put-file ID's that are available to the user for the `put` command.
falcon_rtr_list_scripts
Free · Read-only
Get a list of custom-script ID's that are available to the user for the `runscript` command.
falcon_rtr_update_scripts
Pro · Destructive
Upload a script that replaces an existing Real Time Response custom script.
falcon_rtr_update_scripts_v2
Pro · Destructive
Upload a script that replaces an existing Real Time Response custom script.

Real Time Response (Audit)

ToolWhat it does
falcon_rtr_audit_sessions
Free · Read-only
Get all the RTR sessions created for a customer in a specified duration.

Report Executions

ToolWhat it does
falcon_report_executions_get
Free · Read-only
Retrieve report details for the provided report IDs.
falcon_report_executions_query
Free · Read-only
Find all report execution IDs matching the query with filter.
falcon_report_executions_retry
Pro · Destructive
Retries the given scheduled-report executions.

Scheduled Reports

ToolWhat it does
falcon_scheduled_reports_get
Free · Read-only
Retrieve scheduled reports for the provided report IDs.
falcon_scheduled_reports_launch
Pro · Destructive
Launch executions of the given scheduled reports immediately, outside their schedule.
falcon_scheduled_reports_query
Free · Read-only
Find all report IDs matching the query with filter.

Spans

ToolWhat it does
falcon_entities_spans_v1
Free · Read-only
Retrieve spans for the provided ids.
falcon_queries_spans_v1
Free · Read-only
Query spans based on the provided filters.

Tools

ToolWhat it does
falcon_entities_tools_v1
Free · Read-only
Retrieve tools entities for the provided id.
falcon_queries_tools_v1
Free · Read-only
Query tools based on the provided filters.

Workflows

ToolWhat it does
falcon_v1_child_executions_query
Free · Read-only
Search for child executions by providing a FQL filter and paging details.
falcon_workflow_activities_combined
Free · Read-only
Search for activities by name.
falcon_workflow_activities_content_combined
Free · Read-only
Search for activities by name.
falcon_workflow_definitions_action
Pro · Destructive
Enable or disable a Falcon Fusion workflow definition, or stop all executions for it.
falcon_workflow_definitions_combined
Free · Read-only
Search workflow definitions based on the provided filter.
falcon_workflow_definitions_delete
Pro · Destructive
Accepts a list of Falcon Fusion workflow definition IDs and deletes those definitions together with all their associated versions.
falcon_workflow_definitions_export
Free · Read-only
Exports a workflow definition for the given definition ID.
falcon_workflow_definitions_import
Pro · Destructive
Imports a Falcon Fusion workflow definition from the provided model.
falcon_workflow_definitions_update
Pro · Destructive
Updates a Falcon Fusion workflow definition from the provided model.
falcon_workflow_execute
Pro · Destructive
Executes an on-demand Falcon Fusion workflow; the body is the JSON trigger payload and the response carries the execution IDs.
falcon_workflow_execute_internal
Pro · Destructive
DECOMMISSIONED by CrowdStrike: executes an on-demand Falcon Fusion workflow with internal workflows permitted; the body is the JSON trigger payload and the response carries the execution IDs.
falcon_workflow_execute_single_node_v1
Pro · Destructive
Executes a single Falcon Fusion activity node, producing an execution marked test_mode=true and single_node_execution=true, associated with a definition ID when one is provided.
falcon_workflow_execution_results
Free · Read-only
Get execution result of a given execution.
falcon_workflow_executions_action
Pro · Destructive
Resume or retry a failed Falcon Fusion workflow execution, or cancel and stop one that is currently running.
falcon_workflow_executions_combined
Free · Read-only
Search workflow executions based on the provided filter.
falcon_workflow_get_human_input_v1
Free · Read-only
Gets one or more specific human inputs by their IDs.
falcon_workflow_mock_execute
Pro · Destructive
Executes a Falcon Fusion workflow definition with mocks.
falcon_workflow_system_definitions_de_provision
Pro · Destructive
Deprovisions a system workflow definition that was previously provisioned on the target CID.
falcon_workflow_system_definitions_promote
Pro · Destructive
Promotes a version of a system definition for a customer that is already provisioned, applying an updated template version to that CID.
falcon_workflow_system_definitions_provision
Pro · Destructive
Provisions a system workflow definition onto the target CID from a template and the supplied parameters.
falcon_workflow_triggers_combined
Free · Read-only
Search for triggers by namespaced identifier, i.e. FalconAudit, Detection, or FalconAudit/Detection/Status.
falcon_workflow_update_human_input_v1
Pro · Destructive
Provides an input in response to a Falcon Fusion human-input action.

Application Security Posture

ToolWhat it does
falcon_create_executor_node
Pro · Write
Create a new relay node.
falcon_create_integration
Pro · Write
Create a new integration.
falcon_create_integration_task
Pro · Write
Create new integration task.
falcon_delete_executor_node
Pro · Destructive
Delete an Application Security Posture Management relay node.
falcon_delete_group
Pro · Destructive
Delete an Application Security Posture Management group.
falcon_delete_integration
Pro · Destructive
Delete an Application Security Posture Management integration by ID.
falcon_delete_integration_task
Pro · Destructive
Delete an Application Security Posture Management integration task by ID.
falcon_delete_tags
Pro · Destructive
Remove tags from Application Security Posture Management entities.
falcon_execute_function_data
Free · Read-only
List the Application Security Posture Management function-data records selected by an ASPM query language expression.
falcon_execute_function_data_count
Free · Read-only
Count the Application Security Posture Management function-data records selected by an ASPM query language expression.
falcon_execute_function_data_query
Free · Read-only
List Application Security Posture Management function-data records using the query-function-data form of the ASPM query language.
falcon_execute_function_data_query_count
Free · Read-only
Count Application Security Posture Management function-data records using the query-function-data form of the ASPM query language.
falcon_execute_functions
Free · Read-only
List Application Security Posture Management functions selected by an ASPM query language expression.
falcon_execute_functions_count
Free · Read-only
Count Application Security Posture Management functions selected by an ASPM query language expression.
falcon_execute_functions_overtime
Free · Read-only
Return Application Security Posture Management function counts as a time series, selected by an ASPM query language expression.
falcon_execute_functions_query
Free · Read-only
List Application Security Posture Management functions using the query-functions form of the ASPM query language.
falcon_execute_functions_query_count
Free · Read-only
Count Application Security Posture Management functions using the query-functions form of the ASPM query language.
falcon_execute_functions_query_overtime
Free · Read-only
Return Application Security Posture Management function counts as a time series, using the query-functions form of the ASPM query language.
falcon_execute_query
Pro · Destructive
Run an arbitrary Application Security Posture Management query supplied in the request body.
falcon_get_cloud_security_integration_state
Free · Read-only
Read whether the Cloud Security integration is enabled.
falcon_get_executor_nodes
Free · Read-only
List the Application Security Posture Management relay nodes.
falcon_get_executor_nodes_metadata
Free · Read-only
Read metadata about the Application Security Posture Management relay nodes.
falcon_get_group_hierarchy
Free · Read-only
Read the Application Security Posture Management group hierarchy, showing how groups nest.
falcon_get_group_v2
Free · Read-only
Read the details of one Application Security Posture Management group.
falcon_get_groups_v2
Free · Read-only
List the Application Security Posture Management groups defined in this Falcon tenant.
falcon_get_integration_tasks
Free · Read-only
List the Application Security Posture Management integration tasks.
falcon_get_integration_tasks_admin
Free · Read-only
List the Application Security Posture Management integration tasks.
falcon_get_integration_tasks_metadata
Free · Read-only
Get metadata about all integration tasks.
falcon_get_integration_tasks_v2
Free · Read-only
List the Application Security Posture Management integration tasks.
falcon_get_integration_types
Free · Read-only
List the integration types Application Security Posture Management supports.
falcon_get_integrations
Free · Read-only
List the Application Security Posture Management integrations configured in this tenant.
falcon_get_integrations_v2
Free · Read-only
List the Application Security Posture Management integrations configured in this tenant.
falcon_get_service_artifacts
Free · Read-only
List the artifacts recorded against Application Security Posture Management services.
falcon_get_service_violation_types
Free · Read-only
List the violation types Application Security Posture Management can raise against a service.
falcon_get_services_count
Free · Read-only
Read the total number of services Application Security Posture Management has inventoried.
falcon_get_tags
Free · Read-only
List the tags defined in Application Security Posture Management.
falcon_get_users_v2
Free · Read-only
List the users known to Application Security Posture Management.
falcon_post_group_v2
Pro · Write
Create group.
falcon_retrieve_relay_instances
Free · Read-only
Read the Application Security Posture Management relay instances.
falcon_run_integration_task
Pro · Destructive
Run an integration task now, against the live systems it is configured to reach.
falcon_run_integration_task_admin
Pro · Destructive
Run an integration task now with admin scope, against the live systems it is configured to reach.
falcon_run_integration_task_v2
Pro · Destructive
Run an integration task now, against the live systems it is configured to reach.
falcon_service_now_get_deployments
Free · Read-only
List the ServiceNow deployment records that Application Security Posture Management has ingested.
falcon_service_now_get_services
Free · Read-only
List the ServiceNow service records that Application Security Posture Management has ingested.
falcon_set_cloud_security_integration_state
Pro · Destructive
Enable or disable a Cloud Security integration.
falcon_update_default_group
Pro · Write
Update default group.
falcon_update_executor_node
Pro · Destructive
Replace a relay node definition.
falcon_update_group
Pro · Write
Update group.
falcon_update_integration
Pro · Destructive
Replace an integration definition.
falcon_update_integration_task
Pro · Destructive
Replace an integration task definition.
falcon_upsert_business_applications
Pro · Destructive
Replace business application records in Application Security Posture Management.
falcon_upsert_tags
Pro · Destructive
Replace the tag set on Application Security Posture Management entities.

Cloud AWS Registration

ToolWhat it does
falcon_cloud_registration_aws_create_account
Pro · Destructive
Register an AWS account with Falcon Cloud Security.
falcon_cloud_registration_aws_delete_account
Pro · Destructive
Deregister an AWS account from Falcon Cloud Security.
falcon_cloud_registration_aws_get_accounts
Free · Read-only
Read the registered AWS account records by account ID or by organization ID.
falcon_cloud_registration_aws_query_accounts
Free · Read-only
Search the AWS accounts registered with Falcon Cloud Security.
falcon_cloud_registration_aws_trigger_health_check
Pro · Destructive
Dispatch a health check scan against the registered AWS accounts now.
falcon_cloud_registration_aws_update_account
Pro · Write
Patches a existing account in our system for a customer.
falcon_cloud_registration_aws_validate_accounts
Pro · Write
Validates the AWS account registration status, and discover organization child accounts if organization is specified.

Cloud Azure Registration

ToolWhat it does
falcon_cloud_reg_azure_get_issue_suppression_values_by_field
Free · Read-only
Retrieve distinct filterable values for issue suppression fields.
falcon_cloud_registration_azure_create_registration
Pro · Destructive
Register an Azure tenant with Falcon Cloud Security.
falcon_cloud_registration_azure_create_suppressions
Pro · Destructive
Create Azure issue suppression rules.
falcon_cloud_registration_azure_delete_legacy_subscription
Pro · Destructive
Deregister a legacy Azure subscription registration.
falcon_cloud_registration_azure_delete_registration
Pro · Destructive
Deregister an Azure tenant from Falcon Cloud Security.
falcon_cloud_registration_azure_delete_suppressions
Pro · Destructive
Delete Azure issue suppression rules.
falcon_cloud_registration_azure_get_issue_values_by_field
Free · Read-only
Retrieve distinct filterable values for issue fields.
falcon_cloud_registration_azure_get_issues
Free · Read-only
Read cloud security issues raised against the registered Azure tenants.
falcon_cloud_registration_azure_get_registration
Free · Read-only
Retrieve existing Azure registration for a tenant.
falcon_cloud_registration_azure_get_script
Free · Read-only
Download Azure deployment script (Terraform or Bicep).
falcon_cloud_registration_azure_get_script_versions
Free · Read-only
Retrieve all available script versions with filtering and sorting.
falcon_cloud_registration_azure_get_suppressions
Free · Read-only
Read the Azure issue suppression rules.
falcon_cloud_registration_azure_trigger_health_check
Pro · Destructive
Dispatch a health check scan against the registered Azure tenants now.
falcon_cloud_registration_azure_update_registration
Pro · Write
Update an existing Azure registration for a tenant.
falcon_cloud_registration_azure_update_suppressions
Pro · Destructive
Update Azure issue suppression rules.
falcon_cloud_registration_azure_validate_registration
Pro · Write
Validate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep).

Cloud Connect AWS

ToolWhat it does
falcon_create_or_update_aws_settings
Pro · Write
Create or update Global Settings which are applicable to all provisioned AWS accounts.
falcon_delete_aws_accounts
Pro · Destructive
Deregister provisioned AWS accounts from Falcon.
falcon_get_aws_accounts
Free · Read-only
Read provisioned AWS account records by ID.
falcon_get_aws_settings
Free · Read-only
Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts.
falcon_provision_aws_accounts
Pro · Destructive
Provision AWS accounts into Falcon.
falcon_query_aws_accounts
Free · Read-only
Search provisioned AWS accounts with an FQL filter and return the full account records.
falcon_query_aws_accounts_for_i_ds
Free · Read-only
Search provisioned AWS accounts with an FQL filter and return the matching account IDs only.
falcon_update_aws_accounts
Pro · Write
Update AWS Accounts by specifying the ID of the account and details to update.
falcon_verify_aws_account_access
Pro · Write
Performs an Access Verification check on the specified AWS Account IDs.

Cloud Google Cloud Registration

ToolWhat it does
falcon_cloud_registration_gcp_create_registration
Pro · Destructive
Register a Google Cloud organization, folder or project with Falcon Cloud Security.
falcon_cloud_registration_gcp_delete_registration
Pro · Destructive
Deregister a Google Cloud registration from Falcon Cloud Security.
falcon_cloud_registration_gcp_get_entities
Free · Read-only
List the Google Cloud organizations, folders and projects known to Falcon Cloud Security, grouped by type.
falcon_cloud_registration_gcp_get_registration
Free · Read-only
Retrieve a Google Cloud Registration.
falcon_cloud_registration_gcp_post_terraform_script
Pro · Write
Generate Google Cloud Terraform deployment scripts (zip files).
falcon_cloud_registration_gcp_put_registration
Pro · Destructive
Replace a Google Cloud registration.
falcon_cloud_registration_gcp_trigger_health_check
Pro · Destructive
Dispatch a health check scan against the registered Google Cloud registrations now.
falcon_cloud_registration_gcp_update_registration
Pro · Write
Update a Google Cloud Registration.

Cloud OCI Registration

ToolWhat it does
falcon_cloud_security_registration_oci_create_account
Pro · Destructive
Register an OCI tenancy with Falcon Cloud Security.
falcon_cloud_security_registration_oci_delete_account
Pro · Destructive
Deregister an OCI tenancy from Falcon Cloud Security.
falcon_cloud_security_registration_oci_get_account
Free · Read-only
Search the registered OCI tenancies and return the full tenancy records.
falcon_cloud_security_registration_oci_rotate_key
Pro · Destructive
Rotate the key for an OCI tenancy.
falcon_cloud_security_registration_oci_update_account
Pro · Write
Patch an existing OCI account in our system for a customer.
falcon_cloud_security_registration_oci_validate_tenancy
Pro · Write
Validate the OCI account in CSPM for a provided CID.

Cloud Policies

ToolWhat it does
falcon_clone_compliance_framework
Pro · Write
Clone an existing compliance framework to create a custom copy.
falcon_create_compliance_control
Pro · Write
Create a new custom compliance control.
falcon_create_compliance_framework
Pro · Write
Create a new custom compliance framework.
falcon_create_rule_mixin0
Pro · Write
Create a new rule.
falcon_create_rule_override
Pro · Destructive
Create a cloud policy rule override.
falcon_create_suppression_rule
Pro · Destructive
Create a cloud finding suppression rule.
falcon_delete_compliance_control
Pro · Destructive
Delete a compliance control, together with its rule assignments.
falcon_delete_compliance_framework
Pro · Destructive
Delete a compliance framework, together with the controls it contains.
falcon_delete_rule_mixin0
Pro · Destructive
Delete a cloud policy rule.
falcon_delete_rule_override
Pro · Destructive
Delete a cloud policy rule override, returning the rule to its default evaluation.
falcon_delete_suppression_rules
Pro · Destructive
Delete cloud finding suppression rules.
falcon_get_compliance_controls
Free · Read-only
Read compliance controls by ID.
falcon_get_compliance_frameworks
Free · Read-only
Read compliance frameworks by ID.
falcon_get_enriched_asset
Free · Read-only
Gets enriched assets that combine a primary resource with all its related resources.
falcon_get_evaluation_result
Free · Read-only
Gets evaluation results based on the provided rule.
falcon_get_rule
Free · Read-only
Read a cloud policy rule by ID.
falcon_get_rule_input_schema
Free · Read-only
Get rule input schema for given resource type.
falcon_get_rule_override
Free · Read-only
Read a cloud policy rule override by ID.
falcon_get_suppression_rules
Free · Read-only
Read cloud finding suppression rules by ID.
falcon_query_compliance_controls
Free · Read-only
Search compliance controls and return the matching control IDs.
falcon_query_compliance_frameworks
Free · Read-only
Search compliance frameworks and return the matching framework IDs.
falcon_query_rule
Free · Read-only
Search cloud policy rules and return the matching rule IDs.
falcon_query_suppression_rules
Free · Read-only
Search cloud finding suppression rules and return the matching IDs.
falcon_rename_section_compliance_framework
Pro · Write
Rename a section in a custom compliance framework.
falcon_replace_control_rules
Pro · Destructive
Replace the rule assignments on a compliance control.
falcon_update_compliance_control
Pro · Write
Update a custom compliance control.
falcon_update_compliance_framework
Pro · Write
Update a custom compliance framework.
falcon_update_rule
Pro · Destructive
Update a cloud policy rule.
falcon_update_rule_override
Pro · Destructive
Update a cloud policy rule override.
falcon_update_suppression_rule
Pro · Destructive
Update a cloud finding suppression rule.

Cloud Security

ToolWhat it does
falcon_combined_cloud_risks
Free · Read-only
Search cloud risks and return the full risk records with their detail, rather than IDs.
falcon_create_cloud_group_external
Pro · Write
Create a Cloud Group.
falcon_delete_cloud_groups_external
Pro · Destructive
Delete cloud groups.
falcon_list_cloud_group_i_ds_external
Free · Read-only
Search cloud groups and return the matching group IDs.
falcon_list_cloud_groups_by_id_external
Free · Read-only
Read cloud group records by ID.
falcon_list_cloud_groups_external
Free · Read-only
Search cloud groups and return the full group records in one call.
falcon_update_cloud_group_external
Pro · Write
Update Cloud Group.

Cloud Security Assets

ToolWhat it does
falcon_cloud_security_assets_combined_application_findings
Free · Read-only
Get findings for an application resource with pagination.
falcon_cloud_security_assets_combined_compliance_by_account
Free · Read-only
Gets combined compliance data aggregated by account and region.
falcon_cloud_security_assets_entities_get
Free · Read-only
Read cloud asset records by resource ID, up to 100 per call.
falcon_cloud_security_assets_entities_post
Free · Read-only
Read cloud asset records for the resource IDs supplied in the request body, up to 500 per call.
falcon_cloud_security_assets_queries
Free · Read-only
Search the cloud asset inventory and return the matching resource IDs.

Cloud Security Compliance

ToolWhat it does
falcon_cloud_compliance_framework_posture_summaries
Free · Read-only
Get sections and requirements with scores for benchmarks.
falcon_cloud_compliance_rule_posture_summaries
Free · Read-only
Get compliance score and counts for rules.

Cloud Security Detections

ToolWhat it does
falcon_cspm_evaluations_combined_iom_by_rule
Free · Read-only
Read cloud misconfiguration findings grouped by the policy rule that raised them.
falcon_cspm_evaluations_iom_entities
Free · Read-only
Read cloud misconfiguration findings (indicators of misconfiguration) by ID.
falcon_cspm_evaluations_iom_entities_post
Free · Read-only
Read cloud misconfiguration findings for the IDs supplied in the request body, up to 500 per call.
falcon_cspm_evaluations_iom_queries
Free · Read-only
Search cloud misconfiguration findings (indicators of misconfiguration) and return the matching IDs.

Cloud Security Registration Combined

ToolWhat it does
falcon_cloud_registration_cross_provider_get_account_aggregates
Free · Read-only
Read registered cloud account counts by status across every provider at once.

Cloud Security Risks

ToolWhat it does
falcon_cloud_security_timeline_risks_enriched
Free · Read-only
Returns the enriched asset timeline.

Cloud Snapshots

ToolWhat it does
falcon_combined_detections
Free · Read-only
Search infrastructure-as-code detections with an FQL query and return the full detection records.
falcon_create_deployment_entity
Pro · Destructive
Launch a snapshot scan against a live cloud asset.
falcon_get_credentials_iac
Free · Read-only
Return the image registry credentials that infrastructure-as-code scanning uses to pull images.
falcon_get_credentials_mixin0
Free · Read-only
Return the image registry credentials that snapshot scanning uses to pull images.
falcon_get_scan_report
Free · Read-only
Read the snapshot scan report for a scanned instance.
falcon_read_deployments_combined
Free · Read-only
Search snapshot scan jobs and return the full job records in one call.
falcon_read_deployments_entities
Free · Read-only
Read snapshot scan jobs by ID.
falcon_register_cspm_snapshot_account
Pro · Destructive
Register a customer cloud account for snapshot scanning.

Cloud Security Posture Registration

ToolWhat it does
falcon_azure_refresh_certificate
Pro · Destructive
Refresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal.
falcon_connect_cspmgcp_account
Pro · Destructive
Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id.
falcon_create_cspm_aws_account
Pro · Destructive
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
falcon_create_cspm_azure_account
Pro · Destructive
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
falcon_create_cspm_azure_management_group
Pro · Destructive
Register an Azure management group with CSPM.
falcon_create_cspmgcp_account
Pro · Destructive
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
falcon_delete_cspm_aws_account
Pro · Destructive
Deregister an AWS account from CSPM.
falcon_delete_cspm_azure_account
Pro · Destructive
Deregister an Azure account from CSPM.
falcon_delete_cspm_azure_management_group
Pro · Destructive
Deregister an Azure management group from CSPM.
falcon_delete_cspmgcp_account
Pro · Destructive
Deregister a GCP account from CSPM.
falcon_get_behavior_detections
Free · Read-only
List the CSPM indicator-of-attack behavior detections.
falcon_get_configuration_detection_entities
Free · Read-only
Read cloud misconfiguration detections by ID, including custom policy detections as well as default policy detections.
falcon_get_configuration_detection_i_ds_v2
Free · Read-only
Search active cloud misconfiguration detections, including custom policy detections as well as default policy detections, and return the matching IDs.
falcon_get_cspm_aws_account
Free · Read-only
Returns information about the current status of an AWS account.
falcon_get_cspm_aws_account_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
falcon_get_cspm_aws_console_setup_ur_ls
Free · Read-only
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
falcon_get_cspm_azure_account
Free · Read-only
Return information about Azure account registration.
falcon_get_cspm_azure_management_group
Free · Read-only
Return information about Azure management group registration.
falcon_get_cspm_azure_user_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment.
falcon_get_cspm_policies_details
Free · Read-only
Given an array of policy IDs, returns detailed policies information.
falcon_get_cspm_policy
Free · Read-only
Given a policy ID, returns detailed policy information.
falcon_get_cspm_policy_settings
Free · Read-only
Read the current CSPM policy settings, including which policies are enabled and at what severity.
falcon_get_cspm_scan_schedule
Free · Read-only
Read the CSPM scan schedule configuration for one or more cloud platforms.
falcon_get_cspmgcp_account
Free · Read-only
Returns information about the current status of an GCP account.
falcon_get_cspmgcp_service_accounts_ext
Free · Read-only
Returns the service account id and client email for external clients.
falcon_get_cspmgcp_user_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
falcon_get_cspmgcp_validate_accounts_ext
Free · Read-only
Run a synchronous health check against the registered GCP accounts.
falcon_get_ioa_events
Free · Read-only
For CSPM IOA events, gets list of IOA events.
falcon_get_ioa_users
Free · Read-only
For CSPM IOA users, gets list of IOA users.
falcon_patch_cspm_aws_account
Pro · Write
Patches a existing account in our system for a customer.
falcon_update_cspm_azure_account
Pro · Write
Patches a existing account in our system for a customer.
falcon_update_cspm_azure_account_client_id
Pro · Destructive
Update an Azure service account in our system by with the user-created client_id created with the public key we've provided.
falcon_update_cspm_azure_tenant_default_subscription_id
Pro · Write
Update an Azure default subscription_id in our system for given tenant_id.
falcon_update_cspm_policy_settings
Pro · Destructive
Updates a policy setting - can be used to override policy severity or to disable a policy entirely.
falcon_update_cspm_scan_schedule
Pro · Destructive
Update the CSPM scan schedule for one or more cloud platforms.
falcon_update_cspmgcp_account
Pro · Write
Patches a existing account in our system for a customer.
falcon_update_cspmgcp_service_accounts_ext
Pro · Destructive
Patch the GCP service account key that CSPM authenticates with.
falcon_validate_cspmgcp_service_account_ext
Pro · Write
Validates credentials for a service account.

Cloud Registration (D4C)

ToolWhat it does
falcon_connect_d4_cgcp_account
Pro · Destructive
Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id.
falcon_create_d4_c_aws_account
Pro · Destructive
Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access.
falcon_create_d4_cgcp_account
Pro · Destructive
Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access.
falcon_create_discover_cloud_azure_account
Pro · Destructive
Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access.
falcon_delete_d4_c_aws_account
Pro · Destructive
Deregister an AWS account from Falcon Cloud Workload Protection.
falcon_delete_d4_cgcp_account
Pro · Destructive
Deregister a GCP account from Falcon Cloud Workload Protection.
falcon_get_d4_c_aws_account
Free · Read-only
Returns information about the current status of an AWS account.
falcon_get_d4_c_aws_console_setup_ur_ls
Free · Read-only
Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment.
falcon_get_d4_caws_account_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment.
falcon_get_d4_ccgp_account
Free · Read-only
Returns information about the current status of an GCP account.
falcon_get_d4_cgcp_service_accounts_ext
Free · Read-only
Returns the service account id and client email for external clients.
falcon_get_d4_cgcp_user_scripts
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their GCP environment.
falcon_get_d4_cgcp_user_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment.
falcon_get_discover_cloud_azure_account
Free · Read-only
Return information about Azure account registration.
falcon_get_discover_cloud_azure_tenant_i_ds
Free · Read-only
Return available tenant ids for discover for cloud.
falcon_get_discover_cloud_azure_user_scripts
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their Azure environment.
falcon_get_discover_cloud_azure_user_scripts_attachment
Free · Read-only
Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment.
falcon_get_horizon_d4_c_scripts
Free · Read-only
Returns static install scripts for Horizon.
falcon_update_d4_cgcp_service_accounts_ext
Pro · Destructive
Patch the GCP service account key that Falcon Cloud Workload Protection authenticates with.
falcon_update_discover_cloud_azure_account_client_id
Pro · Destructive
Update an Azure service account in our system by with the user-created client_id created with the public key we've provided.

Drift Indicators

ToolWhat it does
falcon_get_drift_indicators_values_by_date
Free · Read-only
Returns the count of Drift Indicators by the date.
falcon_read_drift_indicator_entities
Free · Read-only
Read container drift indicator records by ID.
falcon_read_drift_indicators_count
Free · Read-only
Returns the total count of Drift indicators over a time period.
falcon_search_and_read_drift_indicator_entities
Free · Read-only
Search container drift indicators and return the full records in one call, rather than searching for IDs and reading them separately.
falcon_search_drift_indicators
Free · Read-only
Search container drift indicators and return the matching IDs.

Scanning Orchestrator

ToolWhat it does
falcon_create_schedules
Pro · Destructive
Create agentless scanning schedules.
falcon_delete_schedules
Pro · Destructive
Delete agentless scanning schedules.
falcon_get_combined_schedules
Free · Read-only
Search agentless scanning schedules and return the full schedule records in one call.
falcon_get_schedules
Free · Read-only
Read agentless scanning schedules by ID.
falcon_get_service_types
Free · Read-only
List the service types agentless scanning is allowed to scan.
falcon_search_schedules
Free · Read-only
Search agentless scanning schedules and return the matching IDs.
falcon_trigger_scan_by_schedule
Pro · Destructive
Dispatch the scans defined by a schedule immediately, rather than waiting for the schedule to fire.
falcon_update_schedules
Pro · Destructive
Update agentless scanning schedules.

Serverless Exports

ToolWhat it does
falcon_launch_export_job_mixin0
Pro · Destructive
Launch a serverless vulnerability export job.
falcon_query_export_jobs_mixin0
Free · Read-only
Search serverless vulnerability export jobs and return the matching job IDs.
falcon_read_export_jobs_mixin0
Free · Read-only
Read serverless vulnerability export jobs by ID.

Serverless Vulnerabilities

ToolWhat it does
falcon_get_combined_vulnerabilities_sarif
Free · Read-only
Retrieve all lambda vulnerabilities that match the given query and return in the SARIF format.

Admission Control Policies

ToolWhat it does
falcon_admission_control_add_host_groups
Pro · Destructive
Put an admission control policy into force over one or more further host groups.
falcon_admission_control_add_rule_group_custom_rule
Pro · Write
Add one or more custom Rego rules to a named rule group in an admission control policy.
falcon_admission_control_create_policy
Pro · Write
Create an admission control policy.
falcon_admission_control_create_rule_groups
Pro · Write
Create one or more rule groups and attach them to an existing admission control policy.
falcon_admission_control_delete_policies
Pro · Destructive
Delete an admission control policy.
falcon_admission_control_delete_rule_groups
Pro · Destructive
Delete rule groups from an admission control policy.
falcon_admission_control_get_policies
Free · Read-only
Read full admission control policy records by ID.
falcon_admission_control_query_policies
Free · Read-only
Search admission control policies.
falcon_admission_control_remove_host_groups
Pro · Destructive
Remove one or more host groups from an admission control policy.
falcon_admission_control_remove_rule_group_custom_rule
Pro · Destructive
Delete one or more custom Rego rules from every rule group in an admission control policy.
falcon_admission_control_replace_rule_group_selectors
Pro · Destructive
Replace the labels and namespaces that a rule group inside an admission control policy selects on.
falcon_admission_control_set_rule_group_precedence
Pro · Destructive
Change the evaluation order of the rule groups inside an admission control policy.
falcon_admission_control_update_policy
Pro · Destructive
Update an admission control policy.
falcon_admission_control_update_policy_precedence
Pro · Destructive
Change the order in which admission control policies are evaluated.
falcon_admission_control_update_rule_groups
Pro · Write
Update a rule group in an admission control policy: its name, description, deny-on-error setting, image assessment settings, default rule actions and custom rule actions.

Container Alerts

ToolWhat it does
falcon_read_container_alerts_count
Free · Read-only
Count the container alerts matching the search criteria.
falcon_read_container_alerts_count_by_severity
Free · Read-only
Count container alerts broken down by severity.
falcon_search_and_read_container_alerts
Free · Read-only
Search container alerts and return the full alert records in one call, rather than IDs to look up separately.

Container Detections

ToolWhat it does
falcon_get_runtime_detections_combined_v2
Free · Read-only
Search container runtime detections and return the full records in one call.
falcon_read_combined_detections
Free · Read-only
Search image assessment detections and return the full records in one call.
falcon_read_detections
Free · Read-only
Read full image assessment detection records by ID.
falcon_read_detections_count
Free · Read-only
Count the image assessment detections matching the filter.
falcon_read_detections_count_by_severity
Free · Read-only
Count image assessment detections broken down by severity.
falcon_read_detections_count_by_type
Free · Read-only
Count image assessment detections broken down by detection type.
falcon_search_detections
Free · Read-only
Search image assessment detections.

Container Image Compliance

ToolWhat it does
falcon_ext_aggregate_cluster_assessments
Free · Read-only
Get the compliance assessment totals for each Kubernetes cluster.
falcon_ext_aggregate_failed_containers_by_rules_path
Free · Read-only
Get the containers that failed compliance, grouped by the rule each one failed.
falcon_ext_aggregate_failed_containers_count_by_severity
Free · Read-only
Count the containers that failed compliance, grouped by severity level.
falcon_ext_aggregate_failed_images_by_rules_path
Free · Read-only
Get the container images that failed compliance, grouped by the rule each one failed.
falcon_ext_aggregate_failed_images_count_by_severity
Free · Read-only
Count the container images that failed compliance, grouped by severity level.
falcon_ext_aggregate_failed_rules_by_clusters
Free · Read-only
Get the failed compliance rules for each Kubernetes cluster, grouped by severity level.
falcon_ext_aggregate_failed_rules_by_images
Free · Read-only
Get the container images that have failed compliance rules, with each image failed-rule count grouped by severity.
falcon_ext_aggregate_failed_rules_count_by_severity
Free · Read-only
Count the failed compliance rules, grouped by severity level.
falcon_ext_aggregate_image_assessments
Free · Read-only
Get the compliance assessment totals for each container image.
falcon_ext_aggregate_rules_assessments
Free · Read-only
Get the compliance assessment totals for each compliance rule.
falcon_ext_aggregate_rules_by_status
Free · Read-only
Get the compliance rules grouped by their pass or fail status.

Container Images

ToolWhat it does
falcon_aggregate_image_assessment_history
Free · Read-only
Get the image assessment history over time.
falcon_aggregate_image_count
Free · Read-only
Count the container images matching the filter.
falcon_aggregate_image_count_by_base_os
Free · Read-only
Count container images grouped by base OS distribution.
falcon_aggregate_image_count_by_state
Free · Read-only
Count container images grouped by state.
falcon_combined_base_images
Free · Read-only
Read the base images registered for this customer, filtered by FQL.
falcon_combined_image_by_vulnerability_count
Free · Read-only
Get the container images carrying the most vulnerabilities, ranked highest first.
falcon_combined_image_detail
Free · Read-only
Read full container image records matching the filter, in one call.
falcon_combined_image_issues_summary
Free · Read-only
Get a per-image summary of open issues: image assessment detections, runtime detections, policy results and vulnerabilities.
falcon_combined_image_vulnerability_summary
Free · Read-only
Get a summary of the vulnerabilities affecting one container image.
falcon_create_base_images_entities
Pro · Write
Register one or more base images.
falcon_delete_base_images
Pro · Destructive
Delete base images by base image UUID.
falcon_get_combined_images
Free · Read-only
Read image assessment results for the container images matching the filter.
falcon_read_combined_images_export
Free · Read-only
Read container images for export, with the option to expand each image aggregated vulnerabilities and detections.

Container Packages

ToolWhat it does
falcon_read_packages_by_fixable_vuln_count
Free · Read-only
Get the application packages carrying the most fixable vulnerabilities, ranked highest first.
falcon_read_packages_by_image_count
Free · Read-only
Get the packages used across the most container images, ranked highest first.
falcon_read_packages_by_vuln_count
Free · Read-only
Get the packages carrying the most vulnerabilities, ranked highest first.
falcon_read_packages_combined
Free · Read-only
Read the packages matching the filter, in one call.
falcon_read_packages_combined_export
Free · Read-only
Read packages for export.
falcon_read_packages_combined_v2
Free · Read-only
Read the packages matching the filter, in one call.
falcon_read_packages_count_by_zero_day
Free · Read-only
Count the packages affected by zero-day vulnerabilities.

Container Vulnerabilities

ToolWhat it does
falcon_read_combined_vulnerabilities
Free · Read-only
Read the container vulnerabilities matching the filter.
falcon_read_combined_vulnerabilities_details
Free · Read-only
Read the vulnerability detail for one container image.
falcon_read_combined_vulnerabilities_info
Free · Read-only
Read vulnerability and package information for this customer.
falcon_read_vulnerabilities_by_image_count
Free · Read-only
Get the vulnerabilities affecting the most container images, ranked highest first.
falcon_read_vulnerabilities_publication_date
Free · Read-only
Get the most recently published container vulnerabilities, newest first.
falcon_read_vulnerability_count
Free · Read-only
Count the container vulnerabilities matching the filter.
falcon_read_vulnerability_count_by_actively_exploited
Free · Read-only
Count container vulnerabilities grouped by whether they are actively exploited.
falcon_read_vulnerability_count_by_cps_rating
Free · Read-only
Count container vulnerabilities grouped by CrowdStrike severity rating (csp_rating).
falcon_read_vulnerability_count_by_cvss_score
Free · Read-only
Count container vulnerabilities grouped by CVSS score.
falcon_read_vulnerability_count_by_severity
Free · Read-only
Count container vulnerabilities grouped by severity.

Falcon Container

ToolWhat it does
falcon_create_registry_entities
Pro · Destructive
Register a container registry connection so Falcon can pull and scan its images.
falcon_delete_image_details
Pro · Destructive
Delete container images by ID, together with their assessment results.
falcon_delete_registry_entities
Pro · Destructive
Delete a container registry connection by UUID.
falcon_get_credentials
Free · Read-only
Read the registry credentials held for this customer container image registry integration.
falcon_get_report_by_reference
Free · Read-only
Get the image assessment scan report for an image, addressed by its image reference.
falcon_get_report_by_scan_id
Free · Read-only
Get the image assessment scan report for one scan, addressed by its scan UUID.
falcon_head_image_scan_inventory
Free · Read-only
Get the response headers for the image scan inventory POST without sending an inventory.
falcon_image_matches_policy
Free · Read-only
Check whether a scanned image matches an image assessment policy.
falcon_launch_export_job
Pro · Destructive
Start an export job for a Container Security resource.
falcon_policy_checks
Free · Read-only
Check a container image against the image prevention policies in force.
falcon_post_image_scan_inventory
Pro · Write
Post an image scan inventory.
falcon_query_export_jobs
Free · Read-only
Search Container Security export jobs.
falcon_read_export_jobs
Free · Read-only
Read full Container Security export job records by ID, including each job status.
falcon_read_image_vulnerabilities
Free · Read-only
Read the known vulnerabilities for the container image supplied in the request body.
falcon_read_registry_entities
Free · Read-only
Search the container registry connections registered for this customer, then pass the UUIDs to falcon_read_registry_entities_by_uuid to read the connection records.
falcon_read_registry_entities_by_uuid
Free · Read-only
Read container registry connection records by UUID, up to 100 UUIDs per call.
falcon_update_registry_entities
Pro · Destructive
Update a container registry connection, addressed by its UUID.

Image Assessment Policies

ToolWhat it does
falcon_create_policy_groups
Pro · Write
Create image assessment policy groups.
falcon_delete_policy
Pro · Destructive
Delete an image assessment policy by UUID.
falcon_delete_policy_group
Pro · Destructive
Delete image assessment policy groups.
falcon_image_policy_create_policies
Pro · Write
Create image assessment policies.
falcon_image_policy_update_policies
Pro · Destructive
Update image assessment policies.
falcon_image_policy_update_policy_precedence
Pro · Destructive
Change the order in which image assessment policies are evaluated.
falcon_read_policies
Free · Read-only
Read all image assessment policies.
falcon_read_policy_exclusions
Free · Read-only
Read the image assessment policy exclusions.
falcon_read_policy_groups
Free · Read-only
Read the image assessment policy groups.
falcon_update_policy_exclusions
Pro · Destructive
Update the image assessment policy exclusions.
falcon_update_policy_groups
Pro · Destructive
Update image assessment policy groups.

Kubernetes Container Compliance

ToolWhat it does
falcon_aggregate_assessments_grouped_by_clusters_v2
Free · Read-only
Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types.
falcon_aggregate_assessments_grouped_by_rules_v2
Free · Read-only
Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts.
falcon_aggregate_compliance_by_asset_type
Free · Read-only
Provides aggregated compliance assessment metrics and rule status information, organized by asset type.
falcon_aggregate_compliance_by_cluster_type
Free · Read-only
Provides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type.
falcon_aggregate_compliance_by_framework
Free · Read-only
Provides aggregated compliance assessment metrics and rule status information, organized by compliance framework.
falcon_aggregate_failed_rules_by_clusters_v3
Free · Read-only
Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low).
falcon_aggregate_top_failed_images
Free · Read-only
Retrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low).
falcon_combined_images_findings
Free · Read-only
Returns detailed compliance assessment results for container images, providing the information needed to identify compliance violations.
falcon_combined_nodes_findings
Free · Read-only
Returns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations.
falcon_get_rules_metadata_by_id
Free · Read-only
Read compliance rule detail by rule ID, including the description, the remediation steps and the audit procedure.

Kubernetes Protection

ToolWhat it does
falcon_create_aws_account
Pro · Write
Register an AWS account with Kubernetes Protection and generate its installation script.
falcon_create_azure_subscription
Pro · Write
Register an Azure subscription with Kubernetes Protection.
falcon_delete_aws_accounts_mixin0
Pro · Destructive
Remove AWS accounts from Kubernetes Protection.
falcon_delete_azure_subscription
Pro · Destructive
Remove an Azure subscription from Kubernetes Protection.
falcon_find_containers_by_container_run_time_version
Free · Read-only
Retrieve containers by container_runtime_version.
falcon_find_containers_count_affected_by_zero_day_vulns
Free · Read-only
Retrieve containers count affected by zero day vulnerabilities.
falcon_get_aws_accounts_mixin0
Free · Read-only
List the AWS accounts registered with Kubernetes Protection.
falcon_get_azure_install_script
Free · Read-only
Get the installation script to run for a given Azure tenant ID and subscription IDs.
falcon_get_azure_tenant_config
Free · Read-only
Read the Azure tenant configuration held by Kubernetes Protection.
falcon_get_azure_tenant_i_ds
Free · Read-only
List the Azure subscriptions and tenants known to Kubernetes Protection.
falcon_get_clusters
Free · Read-only
List the Kubernetes clusters acknowledged by Kubernetes Protection.
falcon_get_combined_cloud_clusters
Free · Read-only
List the provisioned cloud accounts together with the Kubernetes clusters known inside them.
falcon_get_helm_values_yaml
Free · Read-only
Get a sample Helm values.yaml file to install alongside the Kubernetes Protection agent Helm chart.
falcon_get_locations
Free · Read-only
List the cloud locations acknowledged by Kubernetes Protection.
falcon_get_static_scripts
Free · Read-only
Get the static bash scripts used during Kubernetes Protection registration.
falcon_group_containers_by_managed
Free · Read-only
Group the containers by Managed.
falcon_list_azure_accounts
Free · Read-only
List the Azure subscriptions registered with Kubernetes Protection.
falcon_patch_azure_service_principal
Pro · Write
Record the Azure application client ID against a tenant ID in Kubernetes Protection.
falcon_post_aggregates_pods
Free · Read-only
Get aggregate query result for pods.
falcon_post_search_kubernetes_iom_entities
Free · Read-only
Search Kubernetes indicators of misconfiguration (IOMs) with the criteria in the request body.
falcon_read_cluster_combined
Free · Read-only
Read full Kubernetes cluster records matching the filter, in one call.
falcon_read_cluster_combined_v2
Free · Read-only
Read full Kubernetes cluster records, in one call.
falcon_read_cluster_count
Free · Read-only
Retrieve cluster counts.
falcon_read_cluster_enrichment
Free · Read-only
Retrieve cluster enrichment data.
falcon_read_clusters_by_date_range_count
Free · Read-only
Retrieve clusters by date range counts.
falcon_read_clusters_by_kubernetes_version_count
Free · Read-only
Bucket clusters by kubernetes version.
falcon_read_clusters_by_status_count
Free · Read-only
Bucket clusters by status.
falcon_read_container_combined
Free · Read-only
Read full container records matching the filter, in one call.
falcon_read_container_count
Free · Read-only
Retrieve container counts.
falcon_read_container_count_by_registry
Free · Read-only
Retrieves a list with the top container image registries.
falcon_read_container_enrichment
Free · Read-only
Retrieve container enrichment data.
falcon_read_container_image_detections_count_by_date
Free · Read-only
Retrieve count of image assessment detections on running containers over a period of time.
falcon_read_container_images_by_most_used
Free · Read-only
Bucket container by image-digest.
falcon_read_container_images_by_state
Free · Read-only
Retrieve count of image states running on containers.
falcon_read_container_vulnerabilities_by_severity_count
Free · Read-only
Retrieve container vulnerabilities by severity counts.
falcon_read_containers_by_date_range_count
Free · Read-only
Retrieve containers by date range counts.
falcon_read_containers_sensor_coverage
Free · Read-only
Bucket containers by agent type and calculate sensor coverage.
falcon_read_deployment_combined
Free · Read-only
Read full Kubernetes deployment records matching the filter, in one call.
falcon_read_deployment_count
Free · Read-only
Retrieve deployment counts.
falcon_read_deployment_enrichment
Free · Read-only
Retrieve deployment enrichment data.
falcon_read_deployments_by_date_range_count
Free · Read-only
Retrieve deployments by date range counts.
falcon_read_distinct_container_image_count
Free · Read-only
Retrieve count of distinct images running on containers.
falcon_read_kubernetes_iom_by_date_range
Free · Read-only
Returns the count of Kubernetes IOMs by the date.
falcon_read_kubernetes_iom_count
Free · Read-only
Returns the total count of Kubernetes IOMs over the past seven days.
falcon_read_kubernetes_iom_entities
Free · Read-only
Read full Kubernetes indicator of misconfiguration (IOM) records by ID.
falcon_read_namespace_count
Free · Read-only
Retrieve namespace counts.
falcon_read_namespaces_by_date_range_count
Free · Read-only
Retrieve namespaces by date range counts.
falcon_read_node_combined
Free · Read-only
Read full Kubernetes node records matching the filter, in one call.
falcon_read_node_count
Free · Read-only
Retrieve node counts.
falcon_read_node_enrichment
Free · Read-only
Retrieve node enrichment data.
falcon_read_nodes_by_cloud_count
Free · Read-only
Bucket nodes by cloud providers.
falcon_read_nodes_by_container_engine_version_count
Free · Read-only
Bucket nodes by their container engine version.
falcon_read_nodes_by_date_range_count
Free · Read-only
Retrieve nodes by date range counts.
falcon_read_pod_combined
Free · Read-only
Read full Kubernetes pod records matching the filter, in one call.
falcon_read_pod_count
Free · Read-only
Retrieve pod counts.
falcon_read_pod_enrichment
Free · Read-only
Retrieve pod enrichment data.
falcon_read_pods_by_date_range_count
Free · Read-only
Retrieve pods by date range counts.
falcon_read_running_container_images
Free · Read-only
Read the images that are running on containers right now.
falcon_read_vulnerable_container_image_count
Free · Read-only
Retrieve count of vulnerable images running on containers.
falcon_regenerate_api_key
Pro · Destructive
Mint a new API key for the docker registry integrations.
falcon_search_and_read_kubernetes_iom_entities
Free · Read-only
Search Kubernetes indicators of misconfiguration (IOMs) and return the full records in one call.
falcon_search_kubernetes_ioms
Free · Read-only
Search Kubernetes indicators of misconfiguration (IOMs).
falcon_trigger_scan
Pro · Destructive
Start a dry run or a full scan of the customer Kubernetes footprint.
falcon_update_aws_account
Pro · Write
Update a registered AWS account in Kubernetes Protection from the query parameters supplied.

Unidentified Containers

ToolWhat it does
falcon_read_unidentified_containers_by_date_range_count
Free · Read-only
Count unidentified containers by date over the last 7 days.
falcon_read_unidentified_containers_count
Free · Read-only
Count the unidentified containers seen over a time period.
falcon_search_and_read_unidentified_containers
Free · Read-only
Search unidentified containers and return the full records in one call, rather than IDs to look up separately.

Access Scopes

ToolWhat it does
falcon_list_access_scopes_external
Free · Read-only
List Access Scopes By ID.
falcon_query_access_scopes_external
Free · Read-only
Query Access Scopes and returns IDs.

API Clients

ToolWhat it does
falcon_create_api_client
Pro · Destructive
Create new API Client.
falcon_delete_api_clients
Pro · Destructive
Delete existing API Client(s) based on API Client ID(s) provided as request parameter(s) 'ids'.
falcon_get_accessible_scopes
Free · Read-only
Get all available scopes for customer.
falcon_get_all_api_client_ids_for_customer
Free · Read-only
Get All API client ID(s) for customer.
falcon_get_api_clients
Free · Read-only
Get API Client(s) based on API Client ID(s) provided as request parameter(s) 'ids'.
falcon_reset_api_client_secret
Pro · Destructive
Reset existing API Client(s)'s secret based on API Client ID(s) provided as request parameter(s) 'ids'.
falcon_update_api_client
Pro · Destructive
Update existing API Client based on API Client ID provided as request parameter 'ids'.

API Integrations

ToolWhat it does
falcon_execute_command
Pro · Destructive
Execute a command.
falcon_execute_command_proxy
Pro · Destructive
Execute a command and proxy the response directly.
falcon_get_combined_plugin_configs
Free · Read-only
Queries for config resources and returns details.

Case Management

ToolWhat it does
falcon_aggregates_access_tags_post_v1
Free · Read-only
Get access tag aggregates.
falcon_aggregates_file_details_post_v1
Free · Read-only
Get file details aggregates as specified via json in the request body.
falcon_aggregates_notification_groups_post_v1
Free · Read-only
Get notification groups aggregations.
falcon_aggregates_notification_groups_post_v2
Free · Read-only
Get notification groups aggregations.
falcon_aggregates_slas_post_v1
Free · Read-only
Get SLA aggregations.
falcon_aggregates_templates_post_v1
Free · Read-only
Get templates aggregations.
falcon_combined_file_details_get_v1
Free · Read-only
Query file details.
falcon_entities_access_tags_get_v1
Free · Read-only
Get access tags.
falcon_entities_alert_evidence_post_v1
Pro · Write
Adds the given list of alert evidence to the specified case.
falcon_entities_case_tags_delete_v1
Pro · Destructive
Removes the specified tags from the specified case.
falcon_entities_case_tags_post_v1
Pro · Write
Adds the given list of tags to the specified case.
falcon_entities_cases_patch_v2
Pro · Write
Updates given fields on the specified case.
falcon_entities_cases_post_v2
Free · Read-only
Retrieves all Cases given their IDs.
falcon_entities_cases_put_v2
Pro · Destructive
Creates the given Case.
falcon_entities_event_evidence_post_v1
Pro · Write
Adds the given list of event evidence to the specified case.
falcon_entities_fields_get_v1
Free · Read-only
Get fields by ID.
falcon_entities_file_details_get_v1
Free · Read-only
Get file details by id.
falcon_entities_file_details_patch_v1
Pro · Write
Update file details.
falcon_entities_files_delete_v1
Pro · Destructive
Delete file details by id.
falcon_entities_files_upload_post_v1
Pro · Write
Upload file for case.
falcon_entities_get_rtr_file_metadata_post_v1
Free · Read-only
gets metadata for a file via RTR without retrieving it.
falcon_entities_merge_post_v1
Pro · Write
Merges a source case into a destination case.
falcon_entities_notification_groups_delete_v1
Pro · Destructive
Delete notification groups by ID.
falcon_entities_notification_groups_delete_v2
Pro · Destructive
Delete notification groups by ID.
falcon_entities_notification_groups_get_v1
Free · Read-only
Get notification groups by ID.
falcon_entities_notification_groups_get_v2
Free · Read-only
Get notification groups by ID.
falcon_entities_notification_groups_patch_v1
Pro · Write
Update notification group.
falcon_entities_notification_groups_patch_v2
Pro · Write
Update notification group.
falcon_entities_notification_groups_post_v1
Pro · Write
Create notification group.
falcon_entities_notification_groups_post_v2
Pro · Write
Create notification group.
falcon_entities_retrieve_rtr_file_post_v1
Pro · Destructive
retrieves a file from host using RTR and adds it to a case.
falcon_entities_retrieve_rtr_recent_file_post_v1
Pro · Write
RetrieveRecentRTRFile retrieves a recently fetched RTR file and adds it to a case.
falcon_entities_slas_delete_v1
Pro · Destructive
Delete SLAs.
falcon_entities_slas_get_v1
Free · Read-only
Get SLAs by ID.
falcon_entities_slas_patch_v1
Pro · Write
Update SLA.
falcon_entities_slas_post_v1
Pro · Write
Create SLA.
falcon_entities_template_snapshots_get_v1
Free · Read-only
Get template snapshots.
falcon_entities_templates_delete_v1
Pro · Destructive
Delete templates.
falcon_entities_templates_export_get_v1
Free · Read-only
Export templates to files in a zip archive.
falcon_entities_templates_get_v1
Free · Read-only
Get templates by ID.
falcon_entities_templates_import_post_v1
Pro · Write
Import a template from a file.
falcon_entities_templates_patch_v1
Pro · Write
Update template.
falcon_entities_templates_post_v1
Pro · Write
Create template.
falcon_queries_access_tags_get_v1
Free · Read-only
Query access tags.
falcon_queries_cases_get_v1
Free · Read-only
Retrieves all Cases IDs that match a given query.
falcon_queries_fields_get_v1
Free · Read-only
Query fields.
falcon_queries_file_details_get_v1
Free · Read-only
Query for ids of file details.
falcon_queries_notification_groups_get_v1
Free · Read-only
Query notification groups.
falcon_queries_notification_groups_get_v2
Free · Read-only
Query notification groups.
falcon_queries_slas_get_v1
Free · Read-only
Query SLAs.
falcon_queries_template_snapshots_get_v1
Free · Read-only
Query template snapshots.
falcon_queries_templates_get_v1
Free · Read-only
Query templates.

Federated Connections

ToolWhat it does
falcon_delete_federated_connections_config
Pro · Destructive
Delete configuration for a federated connection.
falcon_patch_federated_connections_config
Pro · Write
Update configuration for a federated connection.
falcon_post_federated_connections_config
Pro · Write
Create configuration for a federated connection.

Message Center

ToolWhat it does
falcon_aggregate_cases
Free · Read-only
Retrieve aggregate case values based on the matched filter.
falcon_case_add_activity
Pro · Destructive
Add an activity to case.
falcon_case_add_attachment
Pro · Destructive
Upload an attachment for the case.
falcon_create_case_v2
Pro · Destructive
create a new case.
falcon_get_case_activity_by_ids
Free · Read-only
Retrieve activities for given id's.
falcon_get_case_entities_by_i_ds
Free · Read-only
Retrieve message center cases.
falcon_query_activity_by_case_id
Free · Read-only
Retrieve activities id's for a case.
falcon_query_cases_ids_by_filter
Free · Read-only
Retrieve case id's that match the provided filter criteria.

Flight Control (MSSP)

ToolWhat it does
falcon_add_cid_group_members
Pro · Destructive
Add new CID group member.
falcon_add_role
Pro · Destructive
Create a link between user group and CID group, with zero or more additional roles.
falcon_add_user_group_members
Pro · Destructive
Add new user group member.
falcon_create_cid_groups
Pro · Destructive
Create new CID groups.
falcon_create_user_groups
Pro · Destructive
Create new user groups.
falcon_delete_cid_group_members_v2
Pro · Destructive
Delete CID group members.
falcon_delete_cid_groups
Pro · Destructive
Delete CID groups by ID.
falcon_delete_user_group_members
Pro · Destructive
Delete user group members entry.
falcon_delete_user_groups
Pro · Destructive
Delete user groups by ID.
falcon_deleted_roles
Pro · Destructive
Delete links or additional roles between user groups and CID groups.
falcon_get_children
Free · Read-only
Get link to child customer by child CID(s).
falcon_get_children_v2
Free · Read-only
Get link to child customer by child CID(s).
falcon_get_cid_group_by_id
Free · Read-only
Get CID Groups by ID.
falcon_get_cid_group_by_id_v2
Free · Read-only
Get CID Groups by ID.
falcon_get_cid_group_members_by
Free · Read-only
Get CID group members by CID Group ID.
falcon_get_cid_group_members_by_v2
Free · Read-only
Get CID group members by CID Group ID.
falcon_get_roles_by_id
Free · Read-only
Get link between user group and CID group by ID.
falcon_get_user_group_members_by_id
Free · Read-only
Get user group members by user group ID.
falcon_get_user_group_members_by_idv2
Free · Read-only
Get user group members by user group ID.
falcon_get_user_groups_by_id
Free · Read-only
Get user groups by ID.
falcon_get_user_groups_by_idv2
Free · Read-only
Get user groups by ID.
falcon_query_children
Free · Read-only
Query for customers linked as children.
falcon_query_cid_group_members
Free · Read-only
Query a CID groups members by associated CID.
falcon_query_cid_groups
Free · Read-only
Query CID groups.
falcon_query_roles
Free · Read-only
Query links between user groups and CID groups.
falcon_query_user_group_members
Free · Read-only
Query user group member by user UUID.
falcon_query_user_groups
Free · Read-only
Query user groups.
falcon_update_cid_groups
Pro · Destructive
Update existing CID groups.
falcon_update_user_groups
Pro · Destructive
Update existing user group(s).

Next-Gen SIEM

ToolWhat it does
falcon_add_dashboard_labels
Pro · Write
Add multiple labels to a single dashboard.
falcon_add_file_labels
Pro · Write
Add multiple labels to a single file.
falcon_add_saved_query_labels
Pro · Write
Add multiple labels to a saved query.
falcon_bulk_add_dashboard_labels
Pro · Write
Add labels to multiple dashboards (max 100 items, non-transactional).
falcon_bulk_add_lookup_file_labels
Pro · Write
Add labels to multiple lookup files (max 100 items, non-transactional).
falcon_bulk_add_saved_query_labels
Pro · Write
Add labels to multiple saved queries (max 100 items, non-transactional).
falcon_bulk_create_dashboards_from_template
Pro · Write
Create Multiple Dashboards from YAML Templates.
falcon_bulk_create_lookup_files
Pro · Write
Create Multiple Lookup Files.
falcon_bulk_create_saved_queries_from_template
Pro · Write
Create Multiple Saved Queries from LogScale YAML Templates.
falcon_bulk_get_lookup_files
Free · Read-only
Retrieve Multiple Lookup Files by Filenames in NGSIEM.
falcon_bulk_install_parsers
Pro · Write
Installs multiple CrowdStrike-managed out-of-the-box (OOTB) parsers into the customer's repository in a single operation.
falcon_bulk_remove_dashboard_labels
Pro · Destructive
Remove labels from multiple dashboards (max 100 items, non-transactional).
falcon_bulk_remove_lookup_file_labels
Pro · Destructive
Remove labels from multiple lookup files (max 100 items, non-transactional).
falcon_bulk_remove_saved_query_labels
Pro · Destructive
Remove labels from multiple saved queries (max 100 items, non-transactional).
falcon_bulk_update_dashboard_labels
Pro · Write
Replace all labels on multiple dashboards (max 100 items, non-transactional).
falcon_bulk_update_dashboards_from_template
Pro · Write
Update Multiple Dashboards from YAML Templates.
falcon_bulk_update_lookup_file_labels
Pro · Write
Replace all labels on multiple lookup files (max 100 items, non-transactional).
falcon_bulk_update_lookup_files
Pro · Write
Update Multiple Lookup Files.
falcon_bulk_update_saved_queries_from_template
Pro · Write
Update Multiple Saved Queries from LogScale YAML Templates.
falcon_bulk_update_saved_query_labels
Pro · Write
Replace all labels on multiple saved queries (max 100 items, non-transactional).
falcon_clone_parser
Pro · Write
Clone an existing parser with a new name.
falcon_create_dashboard_from_template
Pro · Write
Create Dashboard from LogScale YAML Template in NGSIEM.
falcon_create_lookup_file
Pro · Write
Create Lookup File in NGSIEM.
falcon_create_parser_extension
Pro · Write
Create a Parser extension in NGSIEM for the provided base parser.
falcon_create_parser_from_template
Pro · Write
Create Parser from LogScale YAML Template in NGSIEM.
falcon_create_saved_query
Pro · Write
Create Saved Query from LogScale YAML Template in NGSIEM.
falcon_delete_dashboard
Pro · Destructive
Delete Dashboard in NGSIEM.
falcon_delete_lookup_file
Pro · Destructive
Delete Lookup File in NGSIEM.
falcon_delete_parser
Pro · Destructive
Delete Parser in NGSIEM.
falcon_delete_saved_query
Pro · Destructive
Delete Saved Query in NGSIEM.
falcon_external_create_connector_config
Pro · Write
Create a new configuration for a data connector.
falcon_external_create_data_connection
Pro · Write
Create a new data connection.
falcon_external_delete_connector_configs
Pro · Destructive
Delete data connection config.
falcon_external_delete_data_connection
Pro · Destructive
Delete a data connection.
falcon_external_get_data_connection_by_id
Free · Read-only
Get data connection by ID.
falcon_external_get_data_connection_status
Free · Read-only
Get data connection provisioning status.
falcon_external_get_data_connection_token
Free · Read-only
Get Ingest token for data connection.
falcon_external_list_connector_configs
Free · Read-only
List configurations for a data connector.
falcon_external_list_data_connections
Free · Read-only
List and search data connections.
falcon_external_list_data_connectors
Free · Read-only
List available data connectors.
falcon_external_patch_connector_config
Pro · Write
Patch configurations for a data connector.
falcon_external_regenerate_data_connection_token
Pro · Destructive
DESTRUCTIVE: rotating the ingest token invalidates the one every collector on this data connection is configured with, so ingestion stops until each is updated with the new token.
falcon_external_update_data_connection
Pro · Write
Update a data connection.
falcon_external_update_data_connection_status
Pro · Write
Update data connection status.
falcon_get_dashboard_template
Free · Read-only
Retrieve Dashboard(s) in NGSIEM as LogScale YAML Template.
falcon_get_lookup_file
Free · Read-only
Retrieve Lookup File in NGSIEM.
falcon_get_lookup_from_package_v1
Free · Read-only
Download lookup file in package from NGSIEM.
falcon_get_lookup_from_package_with_namespace_v1
Free · Read-only
Download lookup file in namespaced package from NGSIEM.
falcon_get_lookup_v1
Free · Read-only
Download lookup file from NGSIEM.
falcon_get_parser_template
Free · Read-only
Retrieve Parser in NGSIEM as LogScale YAML Template.
falcon_get_saved_query_template
Free · Read-only
Retrieve Saved Quer(ies) in NGSIEM as LogScale YAML Template.
falcon_get_search_status_v1
Free · Read-only
Get status of search.
falcon_install_parser
Pro · Destructive
Installs a CrowdStrike-managed out-of-the-box (OOTB) parser into the customer's repository.
falcon_list_dashboards
Free · Read-only
List Dashboards in NGSIEM with Pagination and Filtering.
falcon_list_lookup_files
Free · Read-only
List Lookup Files in NGSIEM with Pagination and Filtering.
falcon_list_parsers
Free · Read-only
List Parsers in NGSIEM.
falcon_list_saved_queries
Free · Read-only
List Saved Queries in NGSIEM with Pagination and Filtering.
falcon_remove_dashboard_labels
Pro · Destructive
Remove multiple labels from a single dashboard.
falcon_remove_file_labels
Pro · Destructive
Remove multiple labels from a single file.
falcon_remove_saved_query_labels
Pro · Destructive
Remove multiple labels from a saved query.
falcon_start_search_v1
Pro · Destructive
Initiate search.
falcon_stop_search_v1
Pro · Destructive
Stop search.
falcon_test_parser_from_template
Pro · Write
Test Parser from LogScale YAML Template in NGSIEM.
falcon_update_dashboard_from_template
Pro · Write
Update Dashboard from LogScale YAML Template in NGSIEM.
falcon_update_dashboard_labels
Pro · Destructive
Replace all labels on a single dashboard.
falcon_update_file_labels
Pro · Destructive
Replace all labels on a single file.
falcon_update_lookup_file
Pro · Write
Update an entire Lookup File in NGSIEM.
falcon_update_lookup_file_entries
Pro · Write
Update entries in an existing Lookup File in NGSIEM.
falcon_update_parser
Pro · Write
Update an NGSIEM parser in place.
falcon_update_parser_auto_update_policy
Pro · Destructive
Updates a parser auto update policy - 'on' enables auto-updates, 'off' disables them.
falcon_update_parser_extension
Pro · Write
Update an existing Parser extension in NGSIEM.
falcon_update_parser_from_template
Pro · Write
Update Parser in NGSIEM from YAML Template.
falcon_update_saved_query_from_template
Pro · Write
Update Saved Query from LogScale YAML Template in NGSIEM.
falcon_update_saved_query_labels
Pro · Destructive
Replace all labels on a single saved query.
falcon_upload_lookup_v1
Pro · Write
Upload file to NGSIEM.

User Management

ToolWhat it does
falcon_aggregate_users_v1
Free · Read-only
Get host aggregates as specified via json in request body.
falcon_combined_user_roles_v2
Free · Read-only
Get User Grant(s).
falcon_create_user_v1
Pro · Destructive
Create a new user.
falcon_delete_user_v1
Pro · Destructive
Delete a user permanently.
falcon_entities_roles_getv2
Free · Read-only
Get info about a role.
falcon_entities_roles_v1
Free · Read-only
Get info about a role.
falcon_queries_roles_v1
Free · Read-only
Show role IDs for all roles available in your customer account.
falcon_query_user_v1
Free · Read-only
List user IDs for all users in your customer account.
falcon_retrieve_users_getv1
Free · Read-only
Get info about users including their name, UID and CID by providing user UUIDs.
falcon_update_user_v1
Pro · Destructive
Modify an existing user's first or last name.
falcon_user_action_v1
Pro · Destructive
Apply actions to one or more User.
falcon_user_roles_action_v1
Pro · Destructive
Grant or Revoke one or more role(s) to a user against a CID.