Connect CrowdStrike Falcon
CrowdStrike Falcon is an endpoint detection and response platform. A lightweight sensor on each machine reports what is happening on it, Falcon decides what is a threat, and your analysts work the…
Written By Christopher Scaminaci
Last updated 6 days ago
CrowdStrike Falcon is an endpoint detection and response platform. A lightweight sensor on each machine reports what is happening on it, Falcon decides what is a threat, and your analysts work the resulting alerts. Around that core it also covers cloud posture, containers and Kubernetes, identity protection, vulnerability and exposure management, and Real Time Response — a live remote shell into a managed endpoint. StackJack talks to Falcon through its documented REST API.
Connecting CrowdStrike Falcon to StackJack gives your AI assistant a family of falcon_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. This is the second-largest connector StackJack ships, so the list below is what the tools are for rather than a roster. With them, your AI can:
- Work the alert queue — search alerts, read the full detection detail behind each one, and pull the aggregate counts that tell you whether today is unusual
- Report on the fleet — which machines have the sensor, which are stale or unhealthy, what version each one runs, and which policies actually apply to which group
- Answer "are we exposed to this?" — vulnerability findings per host, exposed assets Falcon discovered on your behalf, misconfiguration findings, and zero trust assessment scores
- Read threat intelligence — indicator, actor and report lookups, and the sandbox verdict for a file already submitted
- Audit cloud and containers — cloud posture findings across AWS, Azure, Google Cloud and OCI, container image vulnerabilities, and Kubernetes cluster inventory
- Review your own configuration — prevention and sensor update policies, exclusions, firewall rules, custom detection rules, users and their roles
- Contain and remediate (on Pro plans) — network-isolate a compromised machine and lift that containment again, move hosts between groups, and act on quarantined files
- Change protection (on Pro plans) — edit prevention, sensor update, response, device control and firewall policies, and manage the exclusions that tell the sensor what to ignore
- Run Real Time Response (on Pro plans) — open a live session to an endpoint and run commands on it
- Administer the platform (on Pro plans) — manage users, roles, API clients, installation tokens, and, for MSSPs, the customer groups behind Flight Control
How StackJack authenticates to CrowdStrike Falcon
Falcon uses an API client: a Client ID and a Client Secret that you create in the Falcon console. StackJack exchanges them for a short-lived access token, keeps that token fresh, and gets a new one automatically when it expires. There is no consent screen, nothing to reauthorize on a schedule, and no per-user sign-in — the connection acts as the API client you create, not as you.
Choose your cloud region first
This is the one decision to get right before anything else, and it is the single most common cause of a failed first connection.
CrowdStrike runs several independent clouds, and your account lives in exactly one of them. StackJack has no way to discover which — CrowdStrike does not publish one, and asking the wrong cloud does not produce a helpful answer. Credentials sent to the wrong region are rejected in a way that looks identical to a wrong secret. So a region mistake reads as a credential problem, and the natural response is to go and rotate a perfectly good key, which does not help.
For that reason StackJack refuses to guess. The region is a required choice on the connector form, and it starts empty rather than pre-selected. If you do not know yours, the address bar of your Falcon console shows it, and CrowdStrike support can confirm it.
Scopes are fixed when you create the key
Falcon API clients carry permissions per service area, with separate Read and Write ticks for each, and those are chosen when the client is created and cannot be changed afterward. Adding a scope later means issuing a new API client and re-entering the credentials in StackJack.
This is worth a few minutes of thought up front, because it is the most common source of confusion after setup. A key that is missing a scope is not broken — it works perfectly for everything it does cover, and refuses everything else. If your AI reports that Falcon refused one particular area while the rest of the connector works normally, that is a missing tick and not a fault.
Grant Read broadly across the areas you want visibility into, and Write only where you actually want StackJack to make changes. Withholding Write is a genuine safety boundary, and it costs you nothing on the reading side.
Steps
- Sign in to the Falcon console as an administrator and open the API clients area under support and resources.
- Create an API client. Give it a name that identifies StackJack, so it is obvious later what the key is for.
- Choose its scopes. At minimum, tick Read on Hosts — StackJack uses that to test the connection. Then add Read for every area you want your AI to see, and Write only where you want it to act.
- Copy the Client ID and Client Secret immediately. Falcon shows the secret exactly once. If you lose it you must create a new client.
- Note your cloud region, as above.
- Enter all three in StackJack. Open Connectors, choose CrowdStrike Falcon, and enter the Client ID, the Client Secret, and your region.
- Run a Test Connection to confirm StackJack can reach Falcon.
If you are an MSSP using Flight Control
If your API client is a parent account that reaches customer accounts through Flight Control, there is one extra field: the customer's CID. Leave it empty and the connection works against your own parent account.
One StackJack connection covers one Falcon customer. If you manage several customers through Flight Control, add a separate connection for each, with that customer's CID. This is deliberate — it means a tool call can never quietly act on the wrong company, because the customer is fixed by the connection rather than chosen per request.
To add one: open Connectors → CrowdStrike Falcon → Add connection, name it after the customer, and enter that customer's CID. Run falcon_query_children on your parent connection to list the child CIDs first. Your AI then names the customer on each call, or you pin an endpoint to one. See Several connections of one connector.
What to know before your AI uses this connector
Some tools reach a live machine
Falcon is not only a reporting system, and several tools take real action on a real endpoint:
- Containment isolates a machine from the network. It is the correct response to a compromise and it is also disruptive: a contained machine stops talking to everything except Falcon. Lifting containment is a separate tool.
- Real Time Response is a remote shell. Opening a session dispatches a live channel to the endpoint, and the administrator variants run commands on it. Every Real Time Response tool is treated as an action that changes a customer environment, including the ones whose names sound like bookkeeping — opening a session and keeping it alive both reach the machine.
- Scans and detonations dispatch work. On-demand scans, network scans and sandbox submissions run against live systems and consume your CrowdStrike quota.
- Host deletion is permanent.
All of these require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.
Some tools change protection itself
Editing a prevention policy, adding an exclusion, or changing a firewall rule group changes what the sensor does on every machine in scope. Turning a protection off, or excluding a path, deliberately blinds the sensor — which is sometimes exactly right and is never routine. StackJack marks these as destructive for that reason, including the partial edits, and the same applies to suppression rules in cloud security: a suppressed finding disappears from the console and from every report.
Reordering rule precedence counts too. It changes which rule wins without changing any rule.
Reading is safe, and there is a lot of it
Roughly three in five tools only read. Searching, reporting, listing, and pulling detail are all available on the Free tier and none of them change anything. Your AI can investigate an incident end to end — alert, host, policy, vulnerabilities, related detections — without touching a single tool marked destructive. Those reads still return your customers' detection and vulnerability detail, so grant them deliberately.
A successful response can still contain failures
This is specific to Falcon and worth knowing, because it can mislead a person as easily as an assistant. When you ask about several items at once, Falcon can succeed at some and fail at others and report the whole call as successful, listing the failures in a separate part of the response. StackJack passes Falcon's response through exactly as received, so nothing is hidden — but "the call succeeded" and "everything you asked for worked" are different statements here. If a bulk result looks short, the explanation is usually in that part of the response.
Finding things, then reading them
Many Falcon searches return matching identifiers rather than records, and a second tool turns those identifiers into detail. Your AI handles this on its own; the reason to know is that a search reporting matches while showing no detail is normal and not an error.
Searches use CrowdStrike's own filter language, which your AI writes for you.
Plans and limits
Read tools are available on the Free tier. Everything that writes, contains, remediates, runs a command or changes a policy is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated CrowdStrike Falcon tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Falcon limits how fast you can call it, and StackJack paces requests and backs off automatically if you are throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. Falcon also caps how deep you can page into a large result: past roughly ten thousand records a search must be narrowed rather than paged further. Your AI will say so if it reaches that point.
Troubleshooting
"CrowdStrike rejected the credentials" — check the region before you touch the key. A correct Client ID and Secret sent to the wrong cloud fails exactly like a wrong secret, and this is the most common first-connection problem. If the region is right, confirm the Client ID and Secret were copied completely, and remember that Falcon shows the secret only once — if it was not captured at creation, create a new API client.
Falcon accepted the key but refused one particular area — the API client is missing a scope. Scopes are fixed when the client is created, so this cannot be granted after the fact: create a new API client with the ticks you need and re-enter the credentials. The connection test will still pass, because it only needs Read on Hosts.
A Flight Control connection is reading the wrong company — check the customer CID on the connection. Empty means your own parent account, which is a legitimate setting and looks identical to a correctly configured one until you read the data.
A search returns matches but no records — that is the normal two-step pattern described above, not a failure.
A bulk operation reports success but did less than expected — read the failures listed in the response. Falcon reports partial batch failures inside an otherwise successful call.
A large report stops partway with a message about paging depth — Falcon limits how far into a result set you can page. Narrow the search, usually by date range, rather than trying to page further.
CrowdStrike Falcon tools
falcon_ · 1409 tools · Free 845 · Pro 564
Certificate Based Exclusions
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create new Certificate Based Exclusions. |
falcon_Pro · Destructive | Delete the exclusions by id. |
falcon_Free · Read-only | Find all exclusion IDs matching the query with filter. |
falcon_Free · Read-only | Search for cert-based exclusions. |
falcon_Pro · Destructive | Updates existing Certificate Based Exclusions. |
falcon_Free · Read-only | Retrieves certificate signing information for a file. |
Content Update Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Content Update Policies by specifying details about the policy to create. |
falcon_Pro · Destructive | Delete a set of Content Update Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Content Update Policies by specifying their IDs. |
falcon_Pro · Destructive | Perform the specified action on the Content Update Policies specified in the request. |
falcon_Free · Read-only | Search for Content Update Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Content Update Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Content Update Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for content versions available for pinning given the category. |
falcon_Pro · Destructive | Sets the precedence of Content Update Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update Content Update Policies by specifying the ID of the policy and details to update. |
Deployments
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Queries for release-notes resources and returns details. |
falcon_Free · Read-only | Queries for releases resources and returns details. |
falcon_Free · Read-only | Get deployment resources by ids. |
falcon_Free · Read-only | returns the release notes for the IDs in the request. |
falcon_Free · Read-only | returns the release notes for the IDs in the request with EA and GA dates in ISO 8601 format. |
falcon_Free · Read-only | Queries for release-notes resources and returns ids. |
Device Content
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve the host content state for a number of ids between 1 and 100. Discover IDs with falcon_queries_states_v1. Returns the raw Falcon envelope: meta, resources and errors. |
falcon_Free · Read-only | Query for the content state of the host. |
Device Control Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Device Control Policies by specifying details about the policy to create. |
falcon_Pro · Destructive | Delete a set of Device Control Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve the configuration for a Default Device Control Policy. |
falcon_Free · Read-only | Get default device control settings (USB and Bluetooth). |
falcon_Free · Read-only | Retrieve a set of Device Control Policies by specifying their IDs. |
falcon_Free · Read-only | Get device control policies for the given filter criteria. |
falcon_Pro · Destructive | Weakens or changes which USB and Bluetooth device classes this policy blocks, for every host in its scope. |
falcon_Pro · Destructive | Weakens or changes USB and Bluetooth enforcement for every host in this device control policy's scope. |
falcon_Pro · Destructive | Perform the specified action on the Device Control Policies specified in the request. |
falcon_Pro · Write | Create/clone a device control policy (USB and Bluetooth). |
falcon_Free · Read-only | Search for Device Control Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Device Control Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Device Control Policy in your environment by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Sets the precedence of Device Control Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update the configuration for a Default Device Control Policy. |
falcon_Pro · Destructive | Update the configuration for Default Device Control Settings. |
falcon_Pro · Destructive | Update Device Control Policies by specifying the ID of the policy and details to update. |
Firewall Management
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Aggregate events for customer. |
falcon_Free · Read-only | Aggregate rules within a policy for customer. |
falcon_Free · Read-only | Aggregate rule groups for customer. |
falcon_Free · Read-only | Aggregate rules for customer. |
falcon_Pro · Write | Create new network locations provided, and return the ID. |
falcon_Pro · Write | Create new rule group on a platform for a customer with a name and description, and return the ID. |
falcon_Pro · Write | Validates the request of creating a new rule group on a platform for a customer with a name and description. |
falcon_Pro · Destructive | Delete network location entities by ID. |
falcon_Pro · Destructive | Delete rule group entities by ID. |
falcon_Free · Read-only | Get rule group entities by ID. |
falcon_Free · Read-only | Get rule entities by ID (64-bit unsigned int as decimal string) or Family ID (32-character hexadecimal string). |
falcon_Free · Read-only | Find all event IDs matching the query with filter. |
falcon_Free · Read-only | Find all rule group IDs matching the query with filter. |
falcon_Free · Read-only | Find all rule IDs matching the query with filter. |
falcon_Free · Read-only | Get events entities by ID and optionally version. |
falcon_Free · Read-only | Get the firewall field specifications by ID. |
falcon_Free · Read-only | Get a summary of network locations entities by ID. |
falcon_Free · Read-only | Get network locations entities by ID. |
falcon_Free · Read-only | Get platforms by ID, e.g., windows or mac or droid. |
falcon_Free · Read-only | Get policy container entities by policy ID. |
falcon_Free · Read-only | Get the firewall field specification IDs for the provided platform. |
falcon_Free · Read-only | Get a list of network location IDs. |
falcon_Free · Read-only | Get the list of platform names. |
falcon_Free · Read-only | Find all firewall rule IDs matching the query with filter, and return them in precedence order. |
falcon_Pro · Write | Updates the network locations provided, and return the ID. |
falcon_Pro · Write | Updates the network locations metadata such as polling_intervals for the cid. |
falcon_Pro · Destructive | Updates the network locations precedence according to the list of ids provided. |
falcon_Pro · Destructive | Update an identified policy container, including local logging functionality. |
falcon_Pro · Destructive | Update name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules. |
falcon_Pro · Write | Validates the request of updating name, description, or enabled status of a rule group, or create, edit, delete, or reorder rules. |
falcon_Pro · Destructive | Updates the network locations provided, and return the ID. |
falcon_Pro · Write | Validates that the test pattern matches the executable filepath glob pattern. |
Firewall Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Firewall Policies by specifying details about the policy to create. |
falcon_Pro · Destructive | Delete a set of Firewall Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Firewall Policies by specifying their IDs. |
falcon_Pro · Destructive | Perform the specified action on the Firewall Policies specified in the request. |
falcon_Free · Read-only | Search for Firewall Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Firewall Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Firewall Policy in your environment by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Sets the precedence of Firewall Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update Firewall Policies by specifying the ID of the policy and details to update. |
Host Groups
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Host Groups by specifying details about the group to create. |
falcon_Pro · Destructive | Delete a set of Host Groups by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Host Groups by specifying their IDs. |
falcon_Pro · Destructive | Perform the specified action on the Host Groups specified in the request. |
falcon_Free · Read-only | Search for members of a Host Group in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Host Groups in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Host Group in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Host Groups in your environment by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Edits a host group in place. |
Host Migration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create a device migration job. |
falcon_Free · Read-only | Query host migration IDs. |
falcon_Free · Read-only | Get host migration details. |
falcon_Free · Read-only | Get destinations for a migration. |
falcon_Free · Read-only | Query migration jobs. |
falcon_Free · Read-only | Get migration job details. |
falcon_Free · Read-only | Get host migration aggregates as specified via json in request body. |
falcon_Pro · Destructive | Perform an action on host migrations. |
falcon_Free · Read-only | Get migration aggregates as specified via json in request body. |
falcon_Pro · Destructive | Perform an action on a migration job. |
Hosts
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search for hosts in your environment by platform, hostname, IP, and other criteria. |
falcon_Free · Read-only | Search for hidden hosts in your environment by platform, hostname, IP, and other criteria. |
falcon_Pro · Destructive | Permanently delete hosts from the system. |
falcon_Pro · Destructive | Performs the specified action on the provided group IDs. |
falcon_Free · Read-only | Get details on one or more hosts by providing host IDs in a POST body. |
falcon_Free · Read-only | Get details on one or more hosts by providing agent IDs (AID). |
falcon_Free · Read-only | Get details on one or more hosts by providing host IDs as a query parameter. |
falcon_Free · Read-only | Get the online status for one or more hosts by specifying each host’s unique ID. |
falcon_Pro · Destructive | Take various actions on the hosts in your environment. |
falcon_Free · Read-only | Get details on one or more hosts by providing host IDs in a POST body. |
falcon_Free · Read-only | Retrieve details about recent login sessions for a set of devices. |
falcon_Free · Read-only | Retrieve details about recent interactive login sessions for a set of devices powered by the Host Timeline. |
falcon_Free · Read-only | Search for hosts in your environment by platform, hostname, IP, and other criteria. |
falcon_Free · Read-only | Search for hosts in your environment by platform, hostname, IP, and other criteria with continuous pagination capability (based on offset pointer which expires after 2 minutes with no maximum limit). |
falcon_Free · Read-only | Retrieve history of IP and MAC addresses of devices. |
falcon_Free · Read-only | Retrieve hidden hosts that match the provided filter criteria. |
falcon_Pro · Destructive | Append or remove one or more Falcon Grouping Tags on one or more hosts. |
Installation Tokens
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search for audit events by providing an FQL filter and paging details. |
falcon_Free · Read-only | Gets the details of one or more audit events by id. |
falcon_Free · Read-only | Check current installation token settings. |
falcon_Pro · Destructive | Update installation token settings. |
falcon_Pro · Destructive | Creates a token. |
falcon_Pro · Destructive | Deletes a token immediately. |
falcon_Free · Read-only | Search for tokens by providing an FQL filter and paging details. |
falcon_Free · Read-only | Gets the details of one or more tokens by id. |
falcon_Pro · Destructive | Updates one or more tokens. |
IOA Exclusions
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create the IOA exclusions. |
falcon_Pro · Destructive | Delete the IOA exclusions by id. |
falcon_Free · Read-only | Get a set of IOA Exclusions by specifying their IDs. |
falcon_Free · Read-only | Search for IOA exclusions. |
falcon_Free · Read-only | Get Self Service IOA Exclusion aggregates as specified via json in the request body. |
falcon_Pro · Destructive | Create new Self Service IOA Exclusions. |
falcon_Pro · Destructive | Delete the Self Service IOA Exclusions rule by id. |
falcon_Pro · Destructive | Create a report of Self Service IOA Exclusions scoped by the given filters. |
falcon_Free · Read-only | Get the Self Service IOA Exclusions rules by id. |
falcon_Free · Read-only | Get Self Service IOA Exclusions rules for matched IFN/CLI for child, parent and grandparent. |
falcon_Free · Read-only | Get defaults for Self Service IOA Exclusions based on provided IFN/CLI for child, parent and grandparent. |
falcon_Free · Read-only | Search for Self Service IOA Exclusions. |
falcon_Pro · Destructive | Update the Self Service IOA Exclusions rule by id. |
falcon_Pro · Destructive | Update the IOA exclusions. |
ML Exclusions
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create the ML exclusions. |
falcon_Pro · Destructive | Delete the ML exclusions by id. |
falcon_Free · Read-only | Get exclusion aggregates as specified via json in request body. |
falcon_Pro · Destructive | Create the exclusions, with ancestor fields. |
falcon_Pro · Destructive | Delete the exclusions by id, with ancestor fields. |
falcon_Free · Read-only | Get all exclusions. |
falcon_Pro · Destructive | Create a report of ML exclusions scoped by the given filters. |
falcon_Free · Read-only | Get the exclusions by id, with ancestor fields. |
falcon_Pro · Destructive | Actions used to manipulate the content of exclusions, with ancestor fields. |
falcon_Pro · Destructive | Executes an SDMF data frame query against exclusion entities. |
falcon_Free · Read-only | Search for exclusions, with ancestor fields. |
falcon_Pro · Destructive | Update the exclusions by id, with ancestor fields. |
falcon_Free · Read-only | Get a set of ML Exclusions by specifying their IDs. |
falcon_Free · Read-only | Search for ML exclusions. |
falcon_Pro · Destructive | Update the ML exclusions. |
Mobile Enrollment
| Tool | What it does |
|---|---|
falcon_Pro · Write | Trigger on-boarding process for a mobile device. |
falcon_Pro · Write | Trigger on-boarding process for a mobile device. |
Prevention Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Prevention Policies by specifying details about the policy to create. |
falcon_Pro · Destructive | Delete a set of Prevention Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Prevention Policies by specifying their IDs. |
falcon_Pro · Destructive | Perform the specified action on the Prevention Policies specified in the request. |
falcon_Free · Read-only | Search for Prevention Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Prevention Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Prevention Policy in your environment by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Sets the precedence of Prevention Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update Prevention Policies by specifying the ID of the policy and details to update. |
Profile Groups
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create a new profile group. |
falcon_Pro · Destructive | Delete profile groups by IDs. |
falcon_Free · Read-only | Get a list of groups with users that belong to them. |
falcon_Free · Read-only | Get profile groups by IDs with full details. |
falcon_Free · Read-only | Get a list of users with the groups that they belong to. |
falcon_Pro · Destructive | Perform actions on profile groups (add/remove roles, user groups, FGA objects). |
falcon_Pro · Destructive | Add or remove users from profile groups. |
falcon_Free · Read-only | Query profile group IDs with FQL filtering, pagination, and sorting. |
falcon_Pro · Write | Update profile group metadata (name, description). |
Response Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Response Policies by specifying details about the policy to create. |
falcon_Pro · Destructive | Delete a set of Response Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Response Policies by specifying their IDs. |
falcon_Pro · Destructive | Perform the specified action on the Response Policies specified in the request. |
falcon_Free · Read-only | Search for Response Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Response policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Response Policies in your environment by providing an FQL filter with sort and/or paging details. |
falcon_Free · Read-only | Search for members of a Response policy in your environment by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Sets the precedence of Response Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update Response Policies by specifying the ID of the policy and details to update. |
Sensor Download
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get sensor installer IDs by provided query. |
falcon_Free · Read-only | Get sensor installer IDs by provided query. |
falcon_Free · Read-only | Get sensor installer IDs by provided query. |
falcon_Free · Read-only | Get CCID to use with sensor installers. |
falcon_Free · Read-only | Get sensor installer details by provided SHA256 IDs. |
falcon_Free · Read-only | Get sensor installer details by provided SHA256 IDs. |
falcon_Free · Read-only | Get sensor installer details by provided SHA256 IDs. |
Sensor Update Policy
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create Sensor Update Policies by specifying details about the policy to create. |
falcon_Pro · Write | Create Sensor Update Policies by specifying details about the policy to create with additional support for uninstall protection. |
falcon_Pro · Destructive | Delete a set of Sensor Update Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Sensor Update Policies by specifying their IDs. |
falcon_Free · Read-only | Retrieve a set of Sensor Update Policies with additional support for uninstall protection by specifying their IDs. |
falcon_Pro · Destructive | Increments a bulk maintenance token. |
falcon_Pro · Destructive | Perform the specified action on the Sensor Update Policies specified in the request. |
falcon_Free · Read-only | Retrieve available builds for use with Sensor Update Policies. |
falcon_Free · Read-only | Retrieve kernel compatibility info for Sensor Update Builds. |
falcon_Free · Read-only | Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for Sensor Update Policies with additional support for uninstall protection in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Retrieve kernel compatibility info for Sensor Update Builds. |
falcon_Free · Read-only | Search for Sensor Update Policies in your environment by providing an FQL filter and paging details. |
falcon_Free · Read-only | Search for members of a Sensor Update Policy in your environment by providing an FQL filter and paging details. |
falcon_Pro · Write | Reveals an uninstall token for a specific device. |
falcon_Pro · Destructive | Sets the precedence of Sensor Update Policies based on the order of IDs specified in the request. |
falcon_Pro · Destructive | Update Sensor Update Policies by specifying the ID of the policy and details to update. |
falcon_Pro · Destructive | Update Sensor Update Policies by specifying the ID of the policy and details to update with additional support for uninstall protection. |
Sensor Usage
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Fetches hourly average. |
falcon_Free · Read-only | Fetches weekly average. |
Sensor Visibility Exclusions
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create the sensor visibility exclusions. |
falcon_Pro · Destructive | Delete the sensor visibility exclusions by id. |
falcon_Free · Read-only | Get a set of Sensor Visibility Exclusions by specifying their IDs. |
falcon_Free · Read-only | Search for sensor visibility exclusions. |
falcon_Pro · Destructive | Update the sensor visibility exclusions. |
Alerts
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search for alert IDs matching an FQL filter. |
falcon_Pro · Destructive | Apply an action to one or more detections by detection ID. |
falcon_Pro · Destructive | Apply an action to one or more alerts by composite ID. |
falcon_Free · Read-only | Retrieves aggregate values for Alerts across all CIDs. |
falcon_Free · Read-only | Search alerts with an FQL filter and get the full records back in one call. |
falcon_Free · Read-only | Read full alert records for the composite IDs you supply. |
Hunting
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Aggregate Hunting Guides. |
falcon_Free · Read-only | Aggregate intelligence queries. |
falcon_Free · Read-only | Creates an Archive Export. |
falcon_Free · Read-only | Retrieves a list of Hunting Guides. |
falcon_Free · Read-only | Retrieves the details of a list of Intelligence queries IDs. |
falcon_Free · Read-only | Search for Hunting Guides that match the provided conditions. |
falcon_Free · Read-only | Search for a list of intelligence queries IDs that match the provided conditions. |
Correlation Rules
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get rules aggregates as specified via json in the request body. |
falcon_Free · Read-only | Search correlation rules with a query and filter and get the full records back in one call, instead of searching for IDs and reading them separately. |
falcon_Free · Read-only | Find all rules matching the query and filter. |
falcon_Free · Read-only | Retrieve latest rule versions by rule IDs. |
falcon_Pro · Destructive | Delete correlation rule versions by ID. |
falcon_Pro · Write | Export correlation rule versions. |
falcon_Pro · Destructive | Import correlation rule versions from an exported payload. |
falcon_Pro · Destructive | Publish an existing correlation rule version. |
falcon_Pro · Destructive | Delete correlation rules by ID. |
falcon_Free · Read-only | Read full correlation rule records for the IDs you supply. |
falcon_Free · Read-only | Retrieve rule versions by IDs. |
falcon_Pro · Destructive | Update existing correlation rules. |
falcon_Pro · Write | Create a correlation rule. |
falcon_Free · Read-only | Retrieve rule templates by IDs. |
falcon_Pro · Write | Create a correlation rule from a CrowdStrike rule template. |
falcon_Free · Read-only | Search for correlation rule IDs matching a query and filter. |
falcon_Free · Read-only | Find all rule version IDs matching the query and filter. |
falcon_Free · Read-only | Search rule template IDs matching the filter. |
Correlation Rules Admin
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Change the owner of an existing correlation rule. |
falcon_Pro · Destructive | Bulk change the owner of existing correlation rules. |
Custom Indicators of Attack
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create a rule inside a Custom IOA rule group and return it. |
falcon_Pro · Write | Create a Custom IOA rule group for a platform, with a name and an optional description, and return it. |
falcon_Pro · Destructive | Delete Custom IOA rule groups by ID. |
falcon_Free · Read-only | Get pattern severities by ID. |
falcon_Free · Read-only | Get platforms by ID. |
falcon_Free · Read-only | Read full Custom IOA rule groups by ID, including the rules they contain. |
falcon_Free · Read-only | Get rule types by ID. |
falcon_Free · Read-only | Get rules by ID and optionally with cid and/or version in the following format: `[cid:]ID[:version]`. |
falcon_Free · Read-only | Read full Custom IOA rules by ID, optionally with a customer ID and a version, in the form [cid:]ID[:version]. |
falcon_Pro · Destructive | Delete rules from a Custom IOA rule group by ID. |
falcon_Pro · Destructive | Update rules inside a Custom IOA rule group and return them. |
falcon_Free · Read-only | Get all pattern severity IDs. |
falcon_Free · Read-only | Get all platform IDs. |
falcon_Free · Read-only | Find all rule groups matching the query with optional filter. |
falcon_Free · Read-only | Search for Custom IOA rule group IDs matching a query, with an optional filter. |
falcon_Free · Read-only | Get all rule type IDs. |
falcon_Free · Read-only | Search for Custom IOA rule IDs matching a query, with an optional filter. |
falcon_Pro · Destructive | Update a Custom IOA rule group. |
falcon_Pro · Destructive | Update the name, description, enabled flag or field values of individual rules in a Custom IOA rule group and return them. |
falcon_Pro · Write | Validate Custom IOA rule field values and, when a test string is supplied, report whether it matches. |
Falcon Identity
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete third party passkey registries. |
falcon_Free · Read-only | Fetches third party passkey registries. |
falcon_Free · Read-only | Query third party passkey registries. |
falcon_Pro · Destructive | Update third party passkey registries. |
Falcon Sandbox
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete a sandbox report by report ID. |
falcon_Pro · Destructive | Remove a sample from the collection, including the file, its metadata and its submissions. |
falcon_Free · Read-only | Read the content of a sandbox memory dump. |
falcon_Free · Read-only | Get extracted strings from a memory dump. |
falcon_Free · Read-only | Get hex view of a memory dump. |
falcon_Free · Read-only | Read a full sandbox report by report ID, including the behavioral analysis. |
falcon_Free · Read-only | Check the status of a sandbox analysis. |
falcon_Free · Read-only | Read the short summary form of a sandbox report by report ID. |
falcon_Free · Read-only | Search for sandbox report IDs with an FQL filter. |
falcon_Free · Read-only | Retrieves a list with sha256 of samples that exist and customer has rights to access them, maximum number of accepted items is 200. This returns matching IDs only, not the records themselves. |
falcon_Free · Read-only | Find submission IDs for uploaded files by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Submit an uploaded file or a URL to Falcon Sandbox for analysis. |
falcon_Pro · Destructive | Upload a file to Falcon Sandbox for analysis. |
Identity Protection
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete Identity Protection policy rules. |
falcon_Free · Read-only | Get policy rules. |
falcon_Free · Read-only | Query policy rule IDs. |
falcon_Free · Read-only | Get sensor aggregates as specified via json in request body. |
falcon_Free · Read-only | Read details for one or more Identity Protection sensors by device ID, supplied in the request body. |
falcon_Pro · Destructive | Run a GraphQL operation against the Identity Protection API. |
falcon_Pro · Destructive | Create an Identity Protection policy rule. |
falcon_Free · Read-only | Search for Identity Protection sensors in the customer environment by hostname, address and other criteria, and return their IDs. |
Intel
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Perform statistical aggregations over incident data. |
falcon_Free · Read-only | Retrieve full details for one or more adversary incidents by their IDs. |
falcon_Free · Read-only | Search for adversary incidents using FQL criteria and return a paginated list of matching incident IDs. |
falcon_Free · Read-only | Read full CrowdStrike Intelligence adversary profiles for the actor IDs you supply. |
falcon_Free · Read-only | Read full CrowdStrike Intelligence indicator records for the indicator IDs you supply. |
falcon_Free · Read-only | Read full CrowdStrike Intelligence reports for the report IDs you supply. |
falcon_Free · Read-only | Read the PDF attachment of a CrowdStrike Intelligence report. |
falcon_Free · Read-only | Retrieve details for rule sets for the specified ids. |
falcon_Free · Read-only | Download an earlier CrowdStrike Intelligence rule set. |
falcon_Free · Read-only | Download the latest CrowdStrike Intelligence rule set. |
falcon_Free · Read-only | Get malware entities for specified ids. |
falcon_Free · Read-only | Export Mitre ATT&CK information for a given malware family. |
falcon_Free · Read-only | Export Mitre ATT&CK information for a given actor. |
falcon_Free · Read-only | Get vulnerabilities. |
falcon_Free · Read-only | Get vulnerabilities IDs. |
falcon_Free · Read-only | Retrieves report and observable IDs associated with the given actor and attacks. |
falcon_Free · Read-only | Search CrowdStrike Intelligence adversaries with an FQL filter and get the full profiles back in one call. |
falcon_Free · Read-only | Search CrowdStrike Intelligence for adversary IDs matching an FQL filter. |
falcon_Free · Read-only | Search CrowdStrike Intelligence indicators with an FQL filter and get the full records back in one call. |
falcon_Free · Read-only | Search CrowdStrike Intelligence for indicator IDs matching an FQL filter. |
falcon_Free · Read-only | Search CrowdStrike Intelligence reports with an FQL filter and get the full records back in one call. |
falcon_Free · Read-only | Search CrowdStrike Intelligence for report IDs matching an FQL filter. |
falcon_Free · Read-only | Search for rule IDs that match provided filter criteria. |
falcon_Free · Read-only | Get malware family names that match provided FQL filters. |
falcon_Free · Read-only | Get malware entities that match provided FQL filters. |
falcon_Free · Read-only | Gets MITRE tactics and techniques for the given actor, returning concatenation of id and tactic and technique ids, example: fancy-bear_TA0011_T1071. This returns matching IDs only, not the records themselves — pass the IDs to falcon_post_mitre_attacks to read the detail. |
falcon_Free · Read-only | Gets MITRE tactics and techniques for the given malware. |
Intelligence Feeds
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Lists the accessible feed types for a given customer. |
falcon_Free · Read-only | Queries the accessible feed types for a customer. |
Intelligence Indicator Graph
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Look up indicator graph records by their value, such as a hash, domain or address, rather than by ID. |
falcon_Free · Read-only | Search the CrowdStrike indicator graph with an FQL filter. |
Indicators of Compromise
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get Actions by ids. |
falcon_Free · Read-only | Query Actions. |
falcon_Free · Read-only | Launch an indicators report creation job. |
falcon_Free · Read-only | Get Indicators aggregates as specified via json in the request body. |
falcon_Free · Read-only | Search custom indicators of compromise with an FQL filter and get the full records back in one call, instead of searching for IDs and reading them separately. |
falcon_Pro · Destructive | Create custom indicators of compromise. |
falcon_Pro · Destructive | Delete custom indicators of compromise by ID. |
falcon_Free · Read-only | Get the number of devices the indicator has run on. |
falcon_Free · Read-only | Get the IDs of devices the indicator has run on. |
falcon_Free · Read-only | Get the number of processes the indicator has run on. |
falcon_Free · Read-only | Read full custom indicator of compromise records for the IDs you supply. |
falcon_Pro · Write | Run a structured data frame query over custom indicators of compromise. |
falcon_Free · Read-only | Search for custom indicator of compromise IDs with an FQL filter. |
falcon_Pro · Destructive | Update custom indicators of compromise by ID. |
falcon_Free · Read-only | Query IOC Types. |
falcon_Free · Read-only | Query Platforms. |
falcon_Free · Read-only | Query Severities. |
Indicator Search
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Number of hosts in your customer account that have observed a given custom IOC. |
falcon_Free · Read-only | Find the hosts that have observed a given custom indicator of compromise, and return their device IDs. |
falcon_Free · Read-only | For the provided ProcessID retrieve the process details. |
falcon_Free · Read-only | Find the processes associated with a given custom indicator of compromise on a specific host, and return their process IDs. |
MalQuery
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Fetch the zip archive of MalQuery samples prepared by an earlier request, protected with the password infected. |
falcon_Free · Read-only | Retrieve indexed files metadata by their hash. |
falcon_Free · Read-only | Get information about search and download quotas in your environment. |
falcon_Free · Read-only | Check the status and results of an asynchronous request, such as hunt or exact-search. |
falcon_Free · Read-only | Search MalQuery for an exact combination of hex patterns and strings, matching samples at byte level. |
falcon_Free · Read-only | Search MalQuery quickly for a combination of hex patterns and strings, matching samples at byte level. |
falcon_Free · Read-only | Schedule a YARA rule to run across the MalQuery corpus. |
On-Demand Scans
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get aggregates on ODS scan-hosts data. |
falcon_Free · Read-only | Get aggregates on ODS scan data. |
falcon_Free · Read-only | Get aggregates on ODS scheduled-scan data. |
falcon_Pro · Destructive | Cancel running on-demand scans by scan ID. |
falcon_Pro · Destructive | Create an on-demand scan and start or schedule it for the hosts named in the request. |
falcon_Pro · Destructive | Delete scheduled on-demand scans by ID. |
falcon_Free · Read-only | Get malicious files by ids. |
falcon_Free · Read-only | Get scan hosts by ids. |
falcon_Free · Read-only | Read full on-demand scan records for the scan IDs you supply. |
falcon_Free · Read-only | Get Scans by IDs. |
falcon_Free · Read-only | Get ScheduledScans by IDs. |
falcon_Free · Read-only | Query malicious files. |
falcon_Free · Read-only | Query scan hosts. |
falcon_Free · Read-only | Search for on-demand scan IDs with an FQL filter. |
falcon_Free · Read-only | Query ScheduledScans. |
falcon_Pro · Write | Launch a job that builds a report of on-demand scan results. |
falcon_Pro · Destructive | Create a scheduled on-demand scan for the hosts named in the request. |
Quarantine
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Returns count of potentially affected quarantined files for each action. |
falcon_Free · Read-only | Get quarantine file aggregates as specified via json in request body. |
falcon_Free · Read-only | Read quarantined file metadata for the IDs you supply. |
falcon_Free · Read-only | Search for quarantined file IDs with an FQL filter. |
falcon_Pro · Destructive | Apply an action to every quarantined file matching an FQL filter. |
falcon_Pro · Destructive | Apply an action to quarantined files by quarantine file ID. |
Quick Scan
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get scans aggregations as specified via json in request body. |
falcon_Free · Read-only | Check the status of a volume scan. |
falcon_Free · Read-only | Find IDs for submitted scans by providing an FQL filter and paging details. |
falcon_Pro · Destructive | Submit a volume of uploaded files for machine-learning scanning. |
Quick Scan Pro
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete a QuickScan Pro file by its SHA256. The stored sample is removed, and any scan that referenced it loses its source file. |
falcon_Pro · Destructive | Delete the result of a QuickScan Pro scan. |
falcon_Free · Read-only | Gets the result of an QuickScan Pro scan. |
falcon_Pro · Destructive | Start a QuickScan Pro scan of a file already uploaded through the QuickScan Pro file endpoint. |
falcon_Free · Read-only | FQL query specifying the filter parameters. |
falcon_Pro · Destructive | Upload a file for QuickScan Pro analysis. |
falcon_Pro · Destructive | Upload a file for QuickScan Pro analysis, as multipart form data or as an octet stream. |
Recon
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get notification exposed data record aggregates as specified via JSON in request body. |
falcon_Free · Read-only | Get notification aggregates as specified via JSON in request body. |
falcon_Pro · Write | Create actions for a monitoring rule. |
falcon_Pro · Write | Launch an asynchronous recon export job and return its job ID. |
falcon_Pro · Write | Create monitoring rules. |
falcon_Pro · Destructive | Delete an action from a monitoring rule by action ID. |
falcon_Pro · Destructive | Delete recon export jobs and the files they produced, by job ID. |
falcon_Pro · Destructive | Delete recon notifications by ID. |
falcon_Pro · Destructive | Delete monitoring rules by ID. |
falcon_Free · Read-only | Get actions based on their IDs. |
falcon_Free · Read-only | Get the status of export jobs based on their IDs. |
falcon_Free · Read-only | Download the file produced by a recon export job. |
falcon_Free · Read-only | Get detailed notifications based on their IDs. |
falcon_Free · Read-only | Read recon notifications for the IDs you supply, including the raw intelligence content behind each one. |
falcon_Free · Read-only | Get notifications exposed data records based on their IDs. |
falcon_Free · Read-only | Get notifications based on their IDs. |
falcon_Free · Read-only | Read recon notifications for the IDs you supply. |
falcon_Free · Read-only | Read full monitoring rules for the IDs you supply. |
falcon_Free · Read-only | Preview rules notification count and distribution. |
falcon_Free · Read-only | Query actions based on provided criteria. |
falcon_Free · Read-only | Query notifications exposed data records based on provided criteria. |
falcon_Free · Read-only | Search for recon notification IDs matching the criteria you provide. |
falcon_Free · Read-only | Search for monitoring rule IDs matching the criteria you provide. |
falcon_Pro · Write | Update an action on a monitoring rule. |
falcon_Pro · Destructive | Update the status or the assignee of recon notifications, in bulk. |
falcon_Pro · Destructive | Update monitoring rules. |
Sample Uploads
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete an archive that was uploaded earlier. |
falcon_Free · Read-only | Retrieves the archives upload operation statuses. |
falcon_Free · Read-only | Retrieves the archives files in chunks. |
falcon_Pro · Destructive | Upload an archive and extract its file list. |
falcon_Pro · Destructive | Upload an archive and extract its file list. |
falcon_Pro · Destructive | Remove a sample from the collection, including the file, its metadata and its submissions. |
falcon_Pro · Write | Extract the files from an archive that was already uploaded and copy them into internal storage so they can be analyzed. |
falcon_Free · Read-only | Retrieves the files extraction operation statuses. |
falcon_Free · Read-only | Retrieves the files extractions in chunks. |
falcon_Pro · Destructive | Upload a file for cloud analysis. |
Tailored Intelligence
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get event body for the provided event ID. |
falcon_Free · Read-only | Read tailored intelligence events for the IDs you supply. |
falcon_Free · Read-only | Read tailored intelligence rules for the IDs you supply. |
falcon_Free · Read-only | Search for tailored intelligence event IDs matching an FQL filter. |
falcon_Free · Read-only | Search for tailored intelligence rule IDs matching an FQL filter. |
Threatgraph
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Read the Threat Graph edges leaving a vertex. |
falcon_Free · Read-only | Look up where an indicator such as a hash, domain name or address has been observed running in the customer environment. |
falcon_Free · Read-only | Read the Threat Graph summary for a vertex ID. |
falcon_Free · Read-only | Retrieve metadata for a ThreatGraph vertex by id. |
falcon_Free · Read-only | Retrieve metadata for a given vertex ID. |
falcon_Free · Read-only | Show all available edge types. |
Configuration Assessment
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search Falcon configuration assessment findings by FQL filter and return the matching host findings in one call. |
falcon_Free · Read-only | Get the details of one or more configuration assessment rules by rule ID. |
Configuration Assessment Evaluation Logic
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get the evaluation logic behind one or more configuration assessment findings, by finding ID. |
Data Protection Configuration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete Falcon Data Protection classifications by ID. |
falcon_Free · Read-only | Get Falcon Data Protection classification records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection classification. |
falcon_Pro · Write | Create a Falcon Data Protection classification, labeling data by what it contains so policies can act on the label. |
falcon_Pro · Write | Create a Falcon Data Protection cloud application - a SaaS destination policies can allow or block. |
falcon_Pro · Destructive | Delete Falcon Data Protection cloud applications by ID. |
falcon_Free · Read-only | Get Falcon Data Protection cloud application records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection cloud application. |
falcon_Pro · Write | Create a Falcon Data Protection content pattern - the keywords or expressions a classification uses to recognize data. |
falcon_Pro · Destructive | Delete Falcon Data Protection content patterns by ID. |
falcon_Free · Read-only | Get Falcon Data Protection content pattern records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection content pattern. |
falcon_Pro · Write | Create a Falcon Data Protection enterprise account, identifying the customer own tenant inside a cloud application so policies can tell corporate destinations from personal ones. |
falcon_Pro · Destructive | Delete Falcon Data Protection enterprise accounts by ID. |
falcon_Free · Read-only | Get Falcon Data Protection enterprise account records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection enterprise account. |
falcon_Free · Read-only | Get Falcon Data Protection file type records by ID. |
falcon_Pro · Write | Create a Falcon Data Protection local application - an endpoint application policies can allow or block from handling classified data. |
falcon_Pro · Destructive | Delete Falcon Data Protection local applications by ID. |
falcon_Free · Read-only | Get Falcon Data Protection local application records by ID. |
falcon_Pro · Write | Create a Falcon Data Protection local application group, bundling applications so one policy rule can name many. |
falcon_Pro · Destructive | Delete Falcon Data Protection local application groups by ID. |
falcon_Free · Read-only | Get Falcon Data Protection local application group records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection local application group. |
falcon_Pro · Write | Update a Falcon Data Protection local application. |
falcon_Pro · Destructive | Delete Falcon Data Protection policies by ID. |
falcon_Free · Read-only | Get Falcon Data Protection policy records by ID. |
falcon_Pro · Destructive | Weakens or changes the Data Protection enforcement applied to every host in this policy's scope. |
falcon_Pro · Write | Create a Falcon Data Protection policy. |
falcon_Pro · Destructive | Set the precedence order of Falcon Data Protection policies. |
falcon_Pro · Write | Create a Falcon Data Protection sensitivity label, mirroring a label from the customer own labeling system. |
falcon_Pro · Destructive | Delete Falcon Data Protection sensitivity labels by ID. |
falcon_Free · Read-only | Get Falcon Data Protection sensitivity label records by ID. |
falcon_Pro · Write | Create a Falcon Data Protection web location - a destination policies can allow or block. |
falcon_Pro · Destructive | Delete Falcon Data Protection web locations by ID. |
falcon_Free · Read-only | Get Falcon Data Protection web location records by ID. |
falcon_Pro · Write | Create a Falcon Data Protection web location group, bundling destinations so one policy rule can name many. |
falcon_Pro · Destructive | Delete Falcon Data Protection web location groups by ID. |
falcon_Free · Read-only | Get Falcon Data Protection web location group records by ID. |
falcon_Pro · Write | Update a Falcon Data Protection web location group. |
falcon_Pro · Write | Update a Falcon Data Protection web location. |
falcon_Free · Read-only | Search Falcon Data Protection classifications by FQL filter, returning classification IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection cloud applications by FQL filter, returning application IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection content patterns by FQL filter, returning content pattern IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection enterprise accounts by FQL filter, returning account IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection file types by FQL filter, returning file type IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection local applications by FQL filter, returning application IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection local application groups by FQL filter, returning group IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection policies by FQL filter, returning policy IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection sensitivity labels by FQL filter, returning label IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection web locations by FQL filter, returning web location IDs only. |
falcon_Free · Read-only | Search Falcon Data Protection web location groups by FQL filter, returning group IDs only. |
Discover
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search Falcon Discover for installed applications by FQL filter and return the full application records in one call, rather than the IDs falcon_query_applications returns. |
falcon_Free · Read-only | Search Falcon Discover for assets by FQL filter and return the full asset records in one call, rather than the IDs falcon_query_hosts returns. |
falcon_Free · Read-only | Get full Falcon Discover account records for one or more account IDs, including the account type, the privilege level and the host the account was seen on. |
falcon_Free · Read-only | Get full Falcon Discover application records for one or more application IDs, including the vendor, the version and the assets the application is installed on. |
falcon_Free · Read-only | Get full Falcon Discover asset records for one or more asset IDs, including the operating system, network addresses, owner and first and last seen times. |
falcon_Free · Read-only | Get full Falcon Discover IoT and operational-technology asset records for one or more asset IDs. |
falcon_Free · Read-only | Get full Falcon Discover login records for one or more login IDs, including the account, the host and the login time. |
falcon_Free · Read-only | Search Falcon Discover for user accounts by FQL filter, returning account IDs only. |
falcon_Free · Read-only | Search Falcon Discover for installed applications by FQL filter, returning application IDs only. |
falcon_Free · Read-only | Search Falcon Discover for assets by FQL filter, returning asset IDs only. |
falcon_Free · Read-only | Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only. |
falcon_Free · Read-only | Search Falcon Discover for IoT and operational-technology assets by FQL filter, returning asset IDs only. |
falcon_Free · Read-only | Search Falcon Discover for login events by FQL filter, returning login IDs only. |
Exposure Management
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over your external attack surface rather than individual assets, for example assets by country, by service or by criticality. |
falcon_Free · Read-only | Fetch a preview of a binary blob attached to an external asset, such as a captured screenshot or service banner. |
falcon_Free · Read-only | Search your mapped subsidiaries by FQL filter and return the full records in one call, rather than the IDs falcon_query_ecosystem_subsidiaries returns. |
falcon_Pro · Destructive | Remove external assets from your external attack surface inventory by ID. |
falcon_Free · Read-only | Get full records for one or more ecosystem subsidiary IDs. |
falcon_Free · Read-only | Get full external asset records for one or more external asset IDs, including the hostname, resolved addresses, open ports, discovered services and how CrowdStrike attributed the asset to you. |
falcon_Pro · Write | Update fields on existing external assets, such as criticality or ownership. |
falcon_Pro · Write | Add external assets to the scanning inventory so CrowdStrike begins attributing and monitoring them. |
falcon_Free · Read-only | Search your mapped subsidiaries and related organizations by FQL filter, returning subsidiary IDs only. |
falcon_Free · Read-only | Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only. |
falcon_Free · Read-only | Search your external attack surface for internet-facing assets by FQL filter, returning external asset IDs only. |
Falcon Complete Dashboard
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over endpoint protection alerts for the Falcon Complete dashboard, rather than the alert records themselves. |
falcon_Free · Read-only | Return counts and groupings over Falcon Complete allowlist tickets, rather than the tickets themselves. |
falcon_Free · Read-only | Return counts and groupings over Falcon Complete blocklist tickets, rather than the tickets themselves. |
falcon_Free · Read-only | Return host and device counts for the Falcon Complete dashboard, grouped by the criteria in the request body. |
falcon_Free · Read-only | Return counts and groupings over Falcon Complete escalation tickets, rather than the tickets themselves. |
falcon_Free · Read-only | DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incident aggregates. |
falcon_Free · Read-only | Return counts and groupings over prevention policy assignment for the Falcon Complete dashboard. |
falcon_Free · Read-only | Return counts and groupings over Falcon Complete remediation tickets, rather than the tickets themselves. |
falcon_Free · Read-only | Return counts and groupings over sensor update policy assignment for the Falcon Complete dashboard. |
falcon_Free · Read-only | Return counts and groupings over Falcon Complete support issue tickets, rather than the tickets themselves. |
falcon_Free · Read-only | Return the total host and device count for the Falcon Complete dashboard. |
falcon_Free · Read-only | Search Falcon Complete device count collections by FQL filter, returning collection IDs only. |
falcon_Free · Read-only | Search Falcon Complete endpoint protection alerts by FQL filter, returning alert IDs only. |
falcon_Free · Read-only | Search Falcon Complete endpoint, identity and Next-Gen SIEM alerts by FQL filter, returning alert IDs only. |
falcon_Free · Read-only | Search Falcon Complete allowlist tickets by FQL filter, returning ticket IDs only. |
falcon_Free · Read-only | Search Falcon Complete blocklist tickets by FQL filter, returning ticket IDs only. |
falcon_Free · Read-only | Search Falcon Complete escalation tickets by FQL filter, returning ticket IDs only. |
falcon_Free · Read-only | DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns incidents. |
falcon_Free · Read-only | Search Falcon Complete remediation tickets by FQL filter, returning ticket IDs only. |
FileVantage
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create a FileVantage rule group. |
falcon_Pro · Write | Create a rule inside a FileVantage rule group, naming the paths, file types and actions to watch. |
falcon_Pro · Destructive | Blinds FileVantage change detection for the window this exclusion covers. |
falcon_Pro · Destructive | Delete FileVantage policies by ID. |
falcon_Pro · Destructive | Delete scheduled exclusions from a FileVantage policy by ID. |
falcon_Pro · Write | Create a FileVantage policy. |
falcon_Pro · Destructive | Delete FileVantage rule groups by ID. |
falcon_Pro · Destructive | Delete rules from a FileVantage rule group by ID. |
falcon_Free · Read-only | Get the configuration of one or more FileVantage rule groups by ID, including the ids of the rules inside them. |
falcon_Free · Read-only | Get the configuration of one or more FileVantage rules by ID, within a rule group. |
falcon_Free · Read-only | Search FileVantage rule groups of a given type, returning rule group IDs only. |
falcon_Pro · Write | Update a FileVantage policy. |
falcon_Pro · Destructive | Set the precedence order of FileVantage policies for a policy type. |
falcon_Pro · Write | Update a rule inside a FileVantage rule group. |
falcon_Free · Read-only | Get the processing results of one or more FileVantage actions by action ID - what a previously started action did and whether it succeeded. |
falcon_Free · Read-only | Get FileVantage change records for one or more change IDs, including the host, the file or registry path, the action and the actor. |
falcon_Free · Read-only | Get the file content FileVantage captured for one change ID, where content capture is enabled on the rule that caught it. |
falcon_Free · Read-only | Get the configuration of one or more FileVantage policies by ID, including the assigned host groups and rule groups. |
falcon_Free · Read-only | Get the configuration of one or more scheduled exclusions from a FileVantage policy. |
falcon_Free · Read-only | Search FileVantage changes by FQL filter, returning change IDs only, using the high-volume search that pages past the classic 10,000-record window with an after cursor. |
falcon_Free · Read-only | Search FileVantage actions by FQL filter, returning action IDs only. |
falcon_Free · Read-only | Search FileVantage changes by FQL filter, returning change IDs only. |
falcon_Free · Read-only | Search FileVantage policies of a given policy type, returning policy IDs only. |
falcon_Free · Read-only | Search the scheduled exclusions inside one FileVantage policy, returning exclusion IDs only. |
falcon_Pro · Destructive | Initiate FileVantage workflows for the supplied change ids. |
falcon_Pro · Destructive | Start a FileVantage action against the supplied change ids. |
falcon_Pro · Destructive | Assign or unassign host groups on a FileVantage policy. |
falcon_Pro · Destructive | Assign or unassign rule groups on a FileVantage policy. |
falcon_Pro · Destructive | Set the precedence order of the rules inside a FileVantage rule group. |
falcon_Pro · Write | Update a FileVantage rule group. |
falcon_Pro · Destructive | Blinds FileVantage change detection for the window this exclusion covers. |
Network Scan Global Configs
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get the tenant-wide network scan configuration for this customer ID, such as default scan windows and global exclusions. |
falcon_Pro · Write | Update the tenant-wide network scan configuration for this customer ID. |
Network Scan Networks
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over network scan targets, rather than the records themselves. |
falcon_Pro · Write | Create network scan targets - the address ranges a scanner is allowed to scan. |
falcon_Pro · Destructive | Delete network scan targets by ID. |
falcon_Free · Read-only | Get network scan target records by ID, including the address ranges and the zone they belong to. |
falcon_Free · Read-only | Search network scan targets by FQL filter, returning network IDs only. |
falcon_Pro · Write | Update network scan targets. |
Network Scan Scan Run Reports
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Download the report for a network scan run. |
Network Scan Scan Runs
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over network scan runs, rather than the records themselves. |
falcon_Pro · Destructive | Start a network scan run - one immediate execution of a scan definition. |
falcon_Free · Read-only | Get network scan run records by ID, including the status, the timing and the findings summary of that execution. |
falcon_Free · Read-only | Search network scan runs by FQL filter, returning scan run IDs only. |
falcon_Pro · Write | Update a network scan run in flight, for example to change its state. |
Network Scan Scanners
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over deployed network scanners, rather than the records themselves. |
falcon_Free · Read-only | Get network scanner records by ID, including the host running the scanner, its version and its health. |
falcon_Free · Read-only | Search deployed network scanners by FQL filter, returning scanner IDs only. |
falcon_Pro · Write | Update the configuration of a deployed network scanner. |
Network Scan Scans
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over network scan definitions, rather than the records themselves. |
falcon_Pro · Destructive | Create a network scan definition - target networks, template and schedule. |
falcon_Pro · Destructive | Delete network scan definitions by ID. |
falcon_Free · Read-only | Get network scan definition records by ID, including the target networks, the template and the schedule. |
falcon_Free · Read-only | Search network scan definitions by FQL filter, returning scan IDs only. |
falcon_Pro · Write | Update a network scan definition. |
Network Scan Templates
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create a reusable network scan template - what to probe and how aggressively. |
falcon_Pro · Destructive | Delete network scan templates by ID. |
falcon_Free · Read-only | Get the setting detail behind the network scan templates - the individual probes and options a template turns on. |
falcon_Free · Read-only | Get network scan template records by ID. |
falcon_Free · Read-only | Search network scan templates by FQL filter, returning template IDs only. |
falcon_Pro · Write | Update a network scan template. |
Network Scan Zones
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Return counts and groupings over network scan zones, rather than the records themselves. |
falcon_Free · Read-only | Search network scan zones by FQL filter and return the full zone records in one call, rather than the IDs falcon_query_zones returns. |
falcon_Pro · Write | Create a network scan zone, grouping address ranges with the scanners allowed to reach them. |
falcon_Pro · Destructive | Delete network scan zones by ID. |
falcon_Free · Read-only | Get network scan zone records by ID. |
falcon_Free · Read-only | Search network scan zones by FQL filter, returning zone IDs only. |
falcon_Pro · Write | Update a network scan zone. |
SaaS Security
| Tool | What it does |
|---|---|
falcon_Pro · Write | Dismiss one affected entity from a SaaS Security posture check, suppressing that entity from the check results. |
falcon_Pro · Write | Dismiss a SaaS Security posture check by ID, suppressing it from the posture view. |
falcon_Free · Read-only | Get the SaaS Security activity feed - user and administrator actions recorded in connected SaaS applications. |
falcon_Free · Read-only | Get SaaS Security alerts - one alert by ID, or the list. |
falcon_Free · Read-only | Get the inventory of SaaS applications CrowdStrike discovered in this tenant, sanctioned and unsanctioned. |
falcon_Free · Read-only | Get the users of a discovered SaaS application, including how they signed in and when they were last active. |
falcon_Free · Read-only | Get the SaaS Security data inventory - the files and data objects held in connected SaaS applications, with their sensitivity classification. |
falcon_Free · Read-only | Get the SaaS Security device inventory - the devices seen accessing connected SaaS applications. |
falcon_Free · Read-only | Get the SaaS application integrations connected to SaaS Security, with their connection status. |
falcon_Free · Read-only | Get the SaaS Security summary metrics - the rollup counters behind the posture dashboard, such as open checks by severity. |
falcon_Free · Read-only | Get the accounts, users or resources a SaaS Security posture check flagged. |
falcon_Free · Read-only | Get the compliance framework mappings for SaaS Security posture checks - which control in which standard each check satisfies. |
falcon_Free · Read-only | Get SaaS Security posture checks - one check by ID, or the list of checks. |
falcon_Free · Read-only | Get the catalog of SaaS applications SaaS Security can connect to. |
falcon_Free · Read-only | Get the SaaS Security system log - the audit trail of SaaS Security own activity, such as connector runs and configuration changes. |
falcon_Free · Read-only | Get the SaaS Security system users - the accounts that administer SaaS Security itself, not the users of the connected applications. |
falcon_Free · Read-only | Get the SaaS Security user inventory - the identities seen across connected SaaS applications, with their roles and privilege level. |
falcon_Pro · Write | Close an open custom SaaS Security integration data upload transaction, committing what was uploaded. |
falcon_Free · Read-only | Get the status of a custom SaaS Security integration build, including how far an in-progress data upload transaction has reached. |
falcon_Pro · Destructive | Reset a custom SaaS Security integration, discarding its in-progress state and any uploaded data that was not committed. |
falcon_Pro · Write | Upload data into an open custom SaaS Security integration transaction. |
Spotlight Evaluation Logic
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search Spotlight evaluation logic by FQL filter and return the full records in one call, rather than the IDs falcon_query_evaluation_logic returns. |
falcon_Free · Read-only | Search and return the evaluation types Spotlight supports, in one call. |
falcon_Free · Read-only | Get Spotlight evaluation logic records by ID. |
falcon_Free · Read-only | Search Spotlight evaluation logic by FQL filter, returning evaluation logic IDs only. |
Spotlight Vulnerabilities
| Tool | What it does |
|---|---|
falcon_Free · Read-only | DECOMMISSIONED: CrowdStrike retired this operation and it no longer returns installed-patch data for hosts. |
falcon_Free · Read-only | Search Falcon Spotlight for vulnerabilities by FQL filter and return the full vulnerability records in one call, rather than the IDs falcon_spotlight_query_vulnerabilities returns. |
falcon_Free · Read-only | Get Spotlight remediation records by ID, first generation. |
falcon_Free · Read-only | Get Spotlight remediation records by ID. |
falcon_Free · Read-only | Get full Spotlight vulnerability records for one or more vulnerability IDs, including the affected host, the CVE, the severity and the ids of the recommended remediations. |
falcon_Free · Read-only | Search Falcon Spotlight for vulnerabilities across your managed hosts by FQL filter, returning vulnerability IDs only. |
Spotlight Vulnerability Metadata
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search Spotlight vulnerability metadata and return the matching records in one call. |
Zero Trust Assessment
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get Zero Trust Assessment scores for specific hosts, by agent ID (AID) and customer ID (CID). |
falcon_Free · Read-only | Find hosts whose Zero Trust Assessment score falls in a range, for one customer ID (CID). |
falcon_Free · Read-only | Get the Zero Trust Assessment audit report for one customer ID (CID) - the tenant-wide rollup of assessment coverage and scoring rather than per-host detail. |
Agent Invocation
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieves the list of of messages that are resulted from the specified invocation. |
falcon_Pro · Destructive | Invoke a specific Agentic Studio agent version by agent ID and version ID with the supplied input and return its completion response. |
falcon_Pro · Destructive | Invoke a published Agentic Studio agent by ID with the supplied input and return its completion response. |
Agent Templates
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve agent template entities for the provided IDs. |
falcon_Free · Read-only | Query agent template IDs with pagination. |
Agent Versions
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve agent version entities for the provided ids. |
falcon_Free · Read-only | Query agent versions based on the provided filters. |
Custom Storage
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete the specified object from a custom-storage collection. |
falcon_Pro · Destructive | Delete the specified object from a versioned custom-storage collection. |
falcon_Free · Read-only | Fetch metadata about an existing collection. |
falcon_Free · Read-only | Fetch metadata about one or more existing custom-storage collections. |
falcon_Free · Read-only | Get the bytes for the specified object. |
falcon_Free · Read-only | Get the metadata for the specified object. |
falcon_Free · Read-only | Get the bytes of the specified schema of the requested collection. |
falcon_Free · Read-only | Get the metadata for the specified schema of the requested collection. |
falcon_Free · Read-only | Get the bytes for the specified object. |
falcon_Free · Read-only | Get the metadata for the specified object. |
falcon_Free · Read-only | List available collection names in alphabetical order. |
falcon_Free · Read-only | List the object keys in the specified collection in alphabetical order. |
falcon_Free · Read-only | List the object keys in the specified collection in alphabetical order. |
falcon_Free · Read-only | Get the list of schemas for the requested collection in reverse version order (latest first). |
falcon_Pro · Destructive | Put a new object at the given key in a custom-storage collection, or overwrite the object already at that key. |
falcon_Pro · Destructive | Put a new object at the given key in a versioned custom-storage collection, or overwrite the object already at that key. |
falcon_Free · Read-only | Search for objects that match the specified filter criteria (returns metadata, not actual objects). |
falcon_Free · Read-only | Search for objects that match the specified filter criteria (returns metadata, not actual objects). |
Delivery Settings
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get Delivery Settings. |
falcon_Pro · Write | Create Delivery Settings. |
Faas Execution
| Tool | What it does |
|---|---|
falcon_Free · Read-only | retrieve a large request body, such as a file, that has spilled into object storage. |
Foundry Logscale
| Tool | What it does |
|---|---|
falcon_Pro · Write | Execute a dynamic saved search. |
falcon_Pro · Write | Execute a saved search. |
falcon_Pro · Write | Populate a saved search. |
falcon_Pro · Write | DECOMMISSIONED: Creates a lookup file. |
falcon_Pro · Destructive | DECOMMISSIONED by CrowdStrike: updates a lookup file. |
falcon_Free · Read-only | Get the results of a saved search. |
falcon_Pro · Write | Asynchronously ingest data into the application repository. |
falcon_Pro · Write | Synchronously ingest data into the application repository. |
falcon_Free · Read-only | Lists available repositories. |
falcon_Free · Read-only | List available views. |
Foundry Lookup Files
| Tool | What it does |
|---|---|
falcon_Pro · Write | Creates a lookup file within a foundry app. |
falcon_Pro · Destructive | Updates a lookup file within a Foundry app. |
Falcon for IT
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Cancel a Falcon for IT task execution. |
falcon_Free · Read-only | Returns full details of scheduled tasks matching the filter query parameter. |
falcon_Pro · Destructive | Creates a new policy of the specified type. |
falcon_Pro · Destructive | Creates a scheduled task from the given request. |
falcon_Pro · Destructive | Creates a task with details from the given request. |
falcon_Pro · Destructive | Creates a task group from the given request. |
falcon_Pro · Destructive | Creates a user group from the given request. |
falcon_Pro · Destructive | Deletes one or more Falcon for IT policies. |
falcon_Pro · Destructive | Delete one or more scheduled tasks by providing the scheduled tasks IDs. |
falcon_Pro · Destructive | Deletes tasks for each provided ID. |
falcon_Pro · Destructive | Delete one or more task groups by providing the task group IDs. |
falcon_Pro · Destructive | Deletes user groups for each provided ids. |
falcon_Free · Read-only | Retrieve tasks associated with the provided file id. |
falcon_Free · Read-only | Get the task execution results from an async search. |
falcon_Free · Read-only | Get the status of an async task execution results. |
falcon_Free · Read-only | Retrieves the configuration for 1 or more policies. |
falcon_Free · Read-only | Returns scheduled tasks for each provided id. |
falcon_Free · Read-only | Get the task execution for the provided task execution IDs. |
falcon_Free · Read-only | Get the status of host executions by providing the execution IDs. |
falcon_Free · Read-only | Returns the list of task executions (and their details) matching the filter query parameter. |
falcon_Free · Read-only | Returns task groups for each provided id. |
falcon_Free · Read-only | Returns full details of task groups matching the filter query parameter. |
falcon_Free · Read-only | Returns tasks for each provided ID. |
falcon_Free · Read-only | Returns full details of tasks matching the filter query parameter. |
falcon_Free · Read-only | Returns user groups for each provided id. |
falcon_Free · Read-only | Returns the list of policy ids matching the filter query parameter. |
falcon_Pro · Destructive | Rerun the Falcon for IT task execution named in the request. |
falcon_Pro · Destructive | Starts a new Falcon for IT task execution from the query data in the request and returns the initiated executions. |
falcon_Free · Read-only | Returns the list of scheduled task IDs matching the filter query parameter. |
falcon_Free · Read-only | Returns the list of task execution IDs matching the filter query parameter. |
falcon_Free · Read-only | Returns the list of task group ids matching the filter query parameter. |
falcon_Free · Read-only | Returns the list of task IDs matching the filter query parameter. |
falcon_Free · Read-only | Returns the list of user group ids matching the filter query parameter. |
falcon_Pro · Destructive | Starts an async task execution results search. |
falcon_Pro · Destructive | Starts a new Falcon for IT task execution from an existing task and returns the initiated executions. |
falcon_Pro · Destructive | Updates a new policy of the specified type. |
falcon_Pro · Destructive | Updates the policy precedence for all Falcon for IT policies on a platform. |
falcon_Pro · Destructive | Manage the host groups assigned to a Falcon for IT policy. |
falcon_Pro · Destructive | Update an existing scheduled task with the supplied info. |
falcon_Pro · Destructive | Update a task with details from the given request. |
falcon_Pro · Destructive | Update a task group for a given id. |
falcon_Pro · Destructive | Update a user group for a given id. |
Knowledge Base Audit Events
| Tool | What it does |
|---|---|
falcon_Free · Read-only | DECOMMISSIONED: Aggregate knowledge base audit events based on the provided msa criteria. |
falcon_Free · Read-only | Get knowledge base audit events with full event details and pagination. |
falcon_Free · Read-only | Retrieve knowledge base audit event entities by their IDs. |
falcon_Free · Read-only | Query knowledge base audit event IDs with pagination and filtering. |
Knowledge Base Files
| Tool | What it does |
|---|---|
falcon_Pro · Write | Upload a file to a knowledge base. |
falcon_Pro · Destructive | Delete a document from an Agentic Studio knowledge base. |
falcon_Pro · Destructive | Update an existing file in an Agentic Studio knowledge base, optionally its description as well as its content. |
falcon_Free · Read-only | Retrieve knowledge base file entities for the provided id. |
falcon_Free · Read-only | Query knowledge base files based on the provided filters. |
Knowledge Bases
| Tool | What it does |
|---|---|
falcon_Free · Read-only | DECOMMISSIONED: Aggregate knowledge bases based on the provided msa criteria. |
falcon_Free · Read-only | Search for knowledge bases with filtering and return full entity details in a single response. |
falcon_Pro · Destructive | Create or update an Agentic Studio knowledge base. |
falcon_Pro · Write | Update an existing knowledge base. |
falcon_Free · Read-only | Retrieve knowledge base entities for the provided id. |
falcon_Free · Read-only | Query knowledge bases based on the provided filters. |
Models
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get Model Entities by IDs. |
falcon_Free · Read-only | Search the models available to Falcon's agentic studio and return their ids. |
Real Time Response
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Batch executes a Real Time Response Active Responder command across every host mapped to the given batch ID. |
falcon_Pro · Destructive | Batch executes a Real Time Response read-only command across every host mapped to the given batch ID. |
falcon_Pro · Destructive | Batch executes the Real Time Response get command across the hosts mapped to a batch ID to retrieve a file from each of them; poll falcon_batch_get_cmd_status for the results. |
falcon_Free · Read-only | Retrieves the status of the specified batch get command. |
falcon_Pro · Destructive | Batch initialize a Real Time Response session on multiple hosts. |
falcon_Pro · Destructive | Batch refresh a Real Time Response session on multiple hosts. |
falcon_Free · Read-only | Get aggregates on session data. |
falcon_Free · Read-only | Get status of an executed active-responder command on a single host. |
falcon_Free · Read-only | Get status of an executed command on a single host. |
falcon_Pro · Destructive | Delete a Real Time Response session file, meaning a file the session get command retrieved. |
falcon_Pro · Destructive | Delete a Real Time Response session file, meaning a file the session get command retrieved. |
falcon_Pro · Destructive | Delete a queued Real Time Response session command. |
falcon_Pro · Destructive | Delete a Real Time Response session. |
falcon_Pro · Destructive | Execute a Real Time Response Active Responder command on a single host, inside a session that is already open. |
falcon_Pro · Destructive | Execute a Real Time Response read-only command on a single host, inside a session that is already open. |
falcon_Pro · Destructive | Initialize a new Real Time Response session with the RTR cloud against a single host. |
falcon_Free · Read-only | Get a list of session_ids. |
falcon_Free · Read-only | Get a list of files for the specified RTR session. |
falcon_Free · Read-only | Get a list of files for the specified RTR session. |
falcon_Free · Read-only | Get queued session metadata by session ID. |
falcon_Free · Read-only | Get session metadata by session id. |
falcon_Pro · Destructive | Refresh the Real Time Response session timeout on a single host. |
Real Time Response (Admin)
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Batch executes a Real Time Response Administrator command across every host mapped to the given batch ID. |
falcon_Free · Read-only | Get status of an executed RTR administrator command on a single host. |
falcon_Pro · Destructive | Upload a new put-file for the Real Time Response put command. |
falcon_Pro · Destructive | Upload a new put-file for the Real Time Response put command. |
falcon_Pro · Destructive | Upload a new custom script for the Real Time Response runscript command. |
falcon_Pro · Destructive | Upload a new custom script for the Real Time Response runscript command. |
falcon_Pro · Destructive | Delete a Real Time Response put-file by ID, one file per call. |
falcon_Pro · Destructive | Delete a Real Time Response custom script by ID, one script per call. |
falcon_Pro · Destructive | Execute a Real Time Response Administrator command on a single host, inside a session that is already open. |
falcon_Free · Read-only | Get Falcon scripts with metadata and content of script. |
falcon_Free · Read-only | Get RTR put file contents for a given file ID. |
falcon_Free · Read-only | Get put-files based on the ID's given. |
falcon_Free · Read-only | Get put-files based on the ID's given. |
falcon_Free · Read-only | Get custom-scripts based on the ID's given. |
falcon_Free · Read-only | Get custom-scripts based on the ID's given. |
falcon_Free · Read-only | Get a list of Falcon script IDs available to the user to run. |
falcon_Free · Read-only | Get a list of put-file ID's that are available to the user for the `put` command. |
falcon_Free · Read-only | Get a list of custom-script ID's that are available to the user for the `runscript` command. |
falcon_Pro · Destructive | Upload a script that replaces an existing Real Time Response custom script. |
falcon_Pro · Destructive | Upload a script that replaces an existing Real Time Response custom script. |
Real Time Response (Audit)
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get all the RTR sessions created for a customer in a specified duration. |
Report Executions
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve report details for the provided report IDs. |
falcon_Free · Read-only | Find all report execution IDs matching the query with filter. |
falcon_Pro · Destructive | Retries the given scheduled-report executions. |
Scheduled Reports
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve scheduled reports for the provided report IDs. |
falcon_Pro · Destructive | Launch executions of the given scheduled reports immediately, outside their schedule. |
falcon_Free · Read-only | Find all report IDs matching the query with filter. |
Spans
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve spans for the provided ids. |
falcon_Free · Read-only | Query spans based on the provided filters. |
Tools
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve tools entities for the provided id. |
falcon_Free · Read-only | Query tools based on the provided filters. |
Workflows
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search for child executions by providing a FQL filter and paging details. |
falcon_Free · Read-only | Search for activities by name. |
falcon_Free · Read-only | Search for activities by name. |
falcon_Pro · Destructive | Enable or disable a Falcon Fusion workflow definition, or stop all executions for it. |
falcon_Free · Read-only | Search workflow definitions based on the provided filter. |
falcon_Pro · Destructive | Accepts a list of Falcon Fusion workflow definition IDs and deletes those definitions together with all their associated versions. |
falcon_Free · Read-only | Exports a workflow definition for the given definition ID. |
falcon_Pro · Destructive | Imports a Falcon Fusion workflow definition from the provided model. |
falcon_Pro · Destructive | Updates a Falcon Fusion workflow definition from the provided model. |
falcon_Pro · Destructive | Executes an on-demand Falcon Fusion workflow; the body is the JSON trigger payload and the response carries the execution IDs. |
falcon_Pro · Destructive | DECOMMISSIONED by CrowdStrike: executes an on-demand Falcon Fusion workflow with internal workflows permitted; the body is the JSON trigger payload and the response carries the execution IDs. |
falcon_Pro · Destructive | Executes a single Falcon Fusion activity node, producing an execution marked test_mode=true and single_node_execution=true, associated with a definition ID when one is provided. |
falcon_Free · Read-only | Get execution result of a given execution. |
falcon_Pro · Destructive | Resume or retry a failed Falcon Fusion workflow execution, or cancel and stop one that is currently running. |
falcon_Free · Read-only | Search workflow executions based on the provided filter. |
falcon_Free · Read-only | Gets one or more specific human inputs by their IDs. |
falcon_Pro · Destructive | Executes a Falcon Fusion workflow definition with mocks. |
falcon_Pro · Destructive | Deprovisions a system workflow definition that was previously provisioned on the target CID. |
falcon_Pro · Destructive | Promotes a version of a system definition for a customer that is already provisioned, applying an updated template version to that CID. |
falcon_Pro · Destructive | Provisions a system workflow definition onto the target CID from a template and the supplied parameters. |
falcon_Free · Read-only | Search for triggers by namespaced identifier, i.e. FalconAudit, Detection, or FalconAudit/Detection/Status. |
falcon_Pro · Destructive | Provides an input in response to a Falcon Fusion human-input action. |
Application Security Posture
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create a new relay node. |
falcon_Pro · Write | Create a new integration. |
falcon_Pro · Write | Create new integration task. |
falcon_Pro · Destructive | Delete an Application Security Posture Management relay node. |
falcon_Pro · Destructive | Delete an Application Security Posture Management group. |
falcon_Pro · Destructive | Delete an Application Security Posture Management integration by ID. |
falcon_Pro · Destructive | Delete an Application Security Posture Management integration task by ID. |
falcon_Pro · Destructive | Remove tags from Application Security Posture Management entities. |
falcon_Free · Read-only | List the Application Security Posture Management function-data records selected by an ASPM query language expression. |
falcon_Free · Read-only | Count the Application Security Posture Management function-data records selected by an ASPM query language expression. |
falcon_Free · Read-only | List Application Security Posture Management function-data records using the query-function-data form of the ASPM query language. |
falcon_Free · Read-only | Count Application Security Posture Management function-data records using the query-function-data form of the ASPM query language. |
falcon_Free · Read-only | List Application Security Posture Management functions selected by an ASPM query language expression. |
falcon_Free · Read-only | Count Application Security Posture Management functions selected by an ASPM query language expression. |
falcon_Free · Read-only | Return Application Security Posture Management function counts as a time series, selected by an ASPM query language expression. |
falcon_Free · Read-only | List Application Security Posture Management functions using the query-functions form of the ASPM query language. |
falcon_Free · Read-only | Count Application Security Posture Management functions using the query-functions form of the ASPM query language. |
falcon_Free · Read-only | Return Application Security Posture Management function counts as a time series, using the query-functions form of the ASPM query language. |
falcon_Pro · Destructive | Run an arbitrary Application Security Posture Management query supplied in the request body. |
falcon_Free · Read-only | Read whether the Cloud Security integration is enabled. |
falcon_Free · Read-only | List the Application Security Posture Management relay nodes. |
falcon_Free · Read-only | Read metadata about the Application Security Posture Management relay nodes. |
falcon_Free · Read-only | Read the Application Security Posture Management group hierarchy, showing how groups nest. |
falcon_Free · Read-only | Read the details of one Application Security Posture Management group. |
falcon_Free · Read-only | List the Application Security Posture Management groups defined in this Falcon tenant. |
falcon_Free · Read-only | List the Application Security Posture Management integration tasks. |
falcon_Free · Read-only | List the Application Security Posture Management integration tasks. |
falcon_Free · Read-only | Get metadata about all integration tasks. |
falcon_Free · Read-only | List the Application Security Posture Management integration tasks. |
falcon_Free · Read-only | List the integration types Application Security Posture Management supports. |
falcon_Free · Read-only | List the Application Security Posture Management integrations configured in this tenant. |
falcon_Free · Read-only | List the Application Security Posture Management integrations configured in this tenant. |
falcon_Free · Read-only | List the artifacts recorded against Application Security Posture Management services. |
falcon_Free · Read-only | List the violation types Application Security Posture Management can raise against a service. |
falcon_Free · Read-only | Read the total number of services Application Security Posture Management has inventoried. |
falcon_Free · Read-only | List the tags defined in Application Security Posture Management. |
falcon_Free · Read-only | List the users known to Application Security Posture Management. |
falcon_Pro · Write | Create group. |
falcon_Free · Read-only | Read the Application Security Posture Management relay instances. |
falcon_Pro · Destructive | Run an integration task now, against the live systems it is configured to reach. |
falcon_Pro · Destructive | Run an integration task now with admin scope, against the live systems it is configured to reach. |
falcon_Pro · Destructive | Run an integration task now, against the live systems it is configured to reach. |
falcon_Free · Read-only | List the ServiceNow deployment records that Application Security Posture Management has ingested. |
falcon_Free · Read-only | List the ServiceNow service records that Application Security Posture Management has ingested. |
falcon_Pro · Destructive | Enable or disable a Cloud Security integration. |
falcon_Pro · Write | Update default group. |
falcon_Pro · Destructive | Replace a relay node definition. |
falcon_Pro · Write | Update group. |
falcon_Pro · Destructive | Replace an integration definition. |
falcon_Pro · Destructive | Replace an integration task definition. |
falcon_Pro · Destructive | Replace business application records in Application Security Posture Management. |
falcon_Pro · Destructive | Replace the tag set on Application Security Posture Management entities. |
Cloud AWS Registration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Register an AWS account with Falcon Cloud Security. |
falcon_Pro · Destructive | Deregister an AWS account from Falcon Cloud Security. |
falcon_Free · Read-only | Read the registered AWS account records by account ID or by organization ID. |
falcon_Free · Read-only | Search the AWS accounts registered with Falcon Cloud Security. |
falcon_Pro · Destructive | Dispatch a health check scan against the registered AWS accounts now. |
falcon_Pro · Write | Patches a existing account in our system for a customer. |
falcon_Pro · Write | Validates the AWS account registration status, and discover organization child accounts if organization is specified. |
Cloud Azure Registration
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve distinct filterable values for issue suppression fields. |
falcon_Pro · Destructive | Register an Azure tenant with Falcon Cloud Security. |
falcon_Pro · Destructive | Create Azure issue suppression rules. |
falcon_Pro · Destructive | Deregister a legacy Azure subscription registration. |
falcon_Pro · Destructive | Deregister an Azure tenant from Falcon Cloud Security. |
falcon_Pro · Destructive | Delete Azure issue suppression rules. |
falcon_Free · Read-only | Retrieve distinct filterable values for issue fields. |
falcon_Free · Read-only | Read cloud security issues raised against the registered Azure tenants. |
falcon_Free · Read-only | Retrieve existing Azure registration for a tenant. |
falcon_Free · Read-only | Download Azure deployment script (Terraform or Bicep). |
falcon_Free · Read-only | Retrieve all available script versions with filtering and sorting. |
falcon_Free · Read-only | Read the Azure issue suppression rules. |
falcon_Pro · Destructive | Dispatch a health check scan against the registered Azure tenants now. |
falcon_Pro · Write | Update an existing Azure registration for a tenant. |
falcon_Pro · Destructive | Update Azure issue suppression rules. |
falcon_Pro · Write | Validate an Azure registration by checking service principal, role assignments and deployment stack (if the deployment method is Bicep). |
Cloud Connect AWS
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create or update Global Settings which are applicable to all provisioned AWS accounts. |
falcon_Pro · Destructive | Deregister provisioned AWS accounts from Falcon. |
falcon_Free · Read-only | Read provisioned AWS account records by ID. |
falcon_Free · Read-only | Retrieve a set of Global Settings which are applicable to all provisioned AWS accounts. |
falcon_Pro · Destructive | Provision AWS accounts into Falcon. |
falcon_Free · Read-only | Search provisioned AWS accounts with an FQL filter and return the full account records. |
falcon_Free · Read-only | Search provisioned AWS accounts with an FQL filter and return the matching account IDs only. |
falcon_Pro · Write | Update AWS Accounts by specifying the ID of the account and details to update. |
falcon_Pro · Write | Performs an Access Verification check on the specified AWS Account IDs. |
Cloud Google Cloud Registration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Register a Google Cloud organization, folder or project with Falcon Cloud Security. |
falcon_Pro · Destructive | Deregister a Google Cloud registration from Falcon Cloud Security. |
falcon_Free · Read-only | List the Google Cloud organizations, folders and projects known to Falcon Cloud Security, grouped by type. |
falcon_Free · Read-only | Retrieve a Google Cloud Registration. |
falcon_Pro · Write | Generate Google Cloud Terraform deployment scripts (zip files). |
falcon_Pro · Destructive | Replace a Google Cloud registration. |
falcon_Pro · Destructive | Dispatch a health check scan against the registered Google Cloud registrations now. |
falcon_Pro · Write | Update a Google Cloud Registration. |
Cloud OCI Registration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Register an OCI tenancy with Falcon Cloud Security. |
falcon_Pro · Destructive | Deregister an OCI tenancy from Falcon Cloud Security. |
falcon_Free · Read-only | Search the registered OCI tenancies and return the full tenancy records. |
falcon_Pro · Destructive | Rotate the key for an OCI tenancy. |
falcon_Pro · Write | Patch an existing OCI account in our system for a customer. |
falcon_Pro · Write | Validate the OCI account in CSPM for a provided CID. |
Cloud Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Clone an existing compliance framework to create a custom copy. |
falcon_Pro · Write | Create a new custom compliance control. |
falcon_Pro · Write | Create a new custom compliance framework. |
falcon_Pro · Write | Create a new rule. |
falcon_Pro · Destructive | Create a cloud policy rule override. |
falcon_Pro · Destructive | Create a cloud finding suppression rule. |
falcon_Pro · Destructive | Delete a compliance control, together with its rule assignments. |
falcon_Pro · Destructive | Delete a compliance framework, together with the controls it contains. |
falcon_Pro · Destructive | Delete a cloud policy rule. |
falcon_Pro · Destructive | Delete a cloud policy rule override, returning the rule to its default evaluation. |
falcon_Pro · Destructive | Delete cloud finding suppression rules. |
falcon_Free · Read-only | Read compliance controls by ID. |
falcon_Free · Read-only | Read compliance frameworks by ID. |
falcon_Free · Read-only | Gets enriched assets that combine a primary resource with all its related resources. |
falcon_Free · Read-only | Gets evaluation results based on the provided rule. |
falcon_Free · Read-only | Read a cloud policy rule by ID. |
falcon_Free · Read-only | Get rule input schema for given resource type. |
falcon_Free · Read-only | Read a cloud policy rule override by ID. |
falcon_Free · Read-only | Read cloud finding suppression rules by ID. |
falcon_Free · Read-only | Search compliance controls and return the matching control IDs. |
falcon_Free · Read-only | Search compliance frameworks and return the matching framework IDs. |
falcon_Free · Read-only | Search cloud policy rules and return the matching rule IDs. |
falcon_Free · Read-only | Search cloud finding suppression rules and return the matching IDs. |
falcon_Pro · Write | Rename a section in a custom compliance framework. |
falcon_Pro · Destructive | Replace the rule assignments on a compliance control. |
falcon_Pro · Write | Update a custom compliance control. |
falcon_Pro · Write | Update a custom compliance framework. |
falcon_Pro · Destructive | Update a cloud policy rule. |
falcon_Pro · Destructive | Update a cloud policy rule override. |
falcon_Pro · Destructive | Update a cloud finding suppression rule. |
Cloud Security
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search cloud risks and return the full risk records with their detail, rather than IDs. |
falcon_Pro · Write | Create a Cloud Group. |
falcon_Pro · Destructive | Delete cloud groups. |
falcon_Free · Read-only | Search cloud groups and return the matching group IDs. |
falcon_Free · Read-only | Read cloud group records by ID. |
falcon_Free · Read-only | Search cloud groups and return the full group records in one call. |
falcon_Pro · Write | Update Cloud Group. |
Cloud Security Assets
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get findings for an application resource with pagination. |
falcon_Free · Read-only | Gets combined compliance data aggregated by account and region. |
falcon_Free · Read-only | Read cloud asset records by resource ID, up to 100 per call. |
falcon_Free · Read-only | Read cloud asset records for the resource IDs supplied in the request body, up to 500 per call. |
falcon_Free · Read-only | Search the cloud asset inventory and return the matching resource IDs. |
Cloud Security Compliance
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get sections and requirements with scores for benchmarks. |
falcon_Free · Read-only | Get compliance score and counts for rules. |
Cloud Security Detections
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Read cloud misconfiguration findings grouped by the policy rule that raised them. |
falcon_Free · Read-only | Read cloud misconfiguration findings (indicators of misconfiguration) by ID. |
falcon_Free · Read-only | Read cloud misconfiguration findings for the IDs supplied in the request body, up to 500 per call. |
falcon_Free · Read-only | Search cloud misconfiguration findings (indicators of misconfiguration) and return the matching IDs. |
Cloud Security Registration Combined
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Read registered cloud account counts by status across every provider at once. |
Cloud Security Risks
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Returns the enriched asset timeline. |
Cloud Snapshots
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search infrastructure-as-code detections with an FQL query and return the full detection records. |
falcon_Pro · Destructive | Launch a snapshot scan against a live cloud asset. |
falcon_Free · Read-only | Return the image registry credentials that infrastructure-as-code scanning uses to pull images. |
falcon_Free · Read-only | Return the image registry credentials that snapshot scanning uses to pull images. |
falcon_Free · Read-only | Read the snapshot scan report for a scanned instance. |
falcon_Free · Read-only | Search snapshot scan jobs and return the full job records in one call. |
falcon_Free · Read-only | Read snapshot scan jobs by ID. |
falcon_Pro · Destructive | Register a customer cloud account for snapshot scanning. |
Cloud Security Posture Registration
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Refresh certificate and returns JSON object(s) that contain the base64 encoded certificate for a service principal. |
falcon_Pro · Destructive | Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. |
falcon_Pro · Destructive | Register an Azure management group with CSPM. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access. |
falcon_Pro · Destructive | Deregister an AWS account from CSPM. |
falcon_Pro · Destructive | Deregister an Azure account from CSPM. |
falcon_Pro · Destructive | Deregister an Azure management group from CSPM. |
falcon_Pro · Destructive | Deregister a GCP account from CSPM. |
falcon_Free · Read-only | List the CSPM indicator-of-attack behavior detections. |
falcon_Free · Read-only | Read cloud misconfiguration detections by ID, including custom policy detections as well as default policy detections. |
falcon_Free · Read-only | Search active cloud misconfiguration detections, including custom policy detections as well as default policy detections, and return the matching IDs. |
falcon_Free · Read-only | Returns information about the current status of an AWS account. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment. |
falcon_Free · Read-only | Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment. |
falcon_Free · Read-only | Return information about Azure account registration. |
falcon_Free · Read-only | Return information about Azure management group registration. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment. |
falcon_Free · Read-only | Given an array of policy IDs, returns detailed policies information. |
falcon_Free · Read-only | Given a policy ID, returns detailed policy information. |
falcon_Free · Read-only | Read the current CSPM policy settings, including which policies are enabled and at what severity. |
falcon_Free · Read-only | Read the CSPM scan schedule configuration for one or more cloud platforms. |
falcon_Free · Read-only | Returns information about the current status of an GCP account. |
falcon_Free · Read-only | Returns the service account id and client email for external clients. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment. |
falcon_Free · Read-only | Run a synchronous health check against the registered GCP accounts. |
falcon_Free · Read-only | For CSPM IOA events, gets list of IOA events. |
falcon_Free · Read-only | For CSPM IOA users, gets list of IOA users. |
falcon_Pro · Write | Patches a existing account in our system for a customer. |
falcon_Pro · Write | Patches a existing account in our system for a customer. |
falcon_Pro · Destructive | Update an Azure service account in our system by with the user-created client_id created with the public key we've provided. |
falcon_Pro · Write | Update an Azure default subscription_id in our system for given tenant_id. |
falcon_Pro · Destructive | Updates a policy setting - can be used to override policy severity or to disable a policy entirely. |
falcon_Pro · Destructive | Update the CSPM scan schedule for one or more cloud platforms. |
falcon_Pro · Write | Patches a existing account in our system for a customer. |
falcon_Pro · Destructive | Patch the GCP service account key that CSPM authenticates with. |
falcon_Pro · Write | Validates credentials for a service account. |
Cloud Registration (D4C)
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Creates a new GCP account with newly-uploaded service account or connects with existing service account with only the following fields: parent_id, parent_type and service_account_id. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a script for them to run in their AWS cloud environment to grant us access. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a new service account for them to add access to in their GCP environment to grant us access. |
falcon_Pro · Destructive | Creates a new account in our system for a customer and generates a script for them to run in their cloud environment to grant us access. |
falcon_Pro · Destructive | Deregister an AWS account from Falcon Cloud Workload Protection. |
falcon_Pro · Destructive | Deregister a GCP account from Falcon Cloud Workload Protection. |
falcon_Free · Read-only | Returns information about the current status of an AWS account. |
falcon_Free · Read-only | Return a URL for customer to visit in their cloud environment to grant us access to their AWS environment. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their AWS environment as a downloadable attachment. |
falcon_Free · Read-only | Returns information about the current status of an GCP account. |
falcon_Free · Read-only | Returns the service account id and client email for external clients. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their GCP environment. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their GCP environment as a downloadable attachment. |
falcon_Free · Read-only | Return information about Azure account registration. |
falcon_Free · Read-only | Return available tenant ids for discover for cloud. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their Azure environment. |
falcon_Free · Read-only | Return a script for customer to run in their cloud environment to grant us access to their Azure environment as a downloadable attachment. |
falcon_Free · Read-only | Returns static install scripts for Horizon. |
falcon_Pro · Destructive | Patch the GCP service account key that Falcon Cloud Workload Protection authenticates with. |
falcon_Pro · Destructive | Update an Azure service account in our system by with the user-created client_id created with the public key we've provided. |
Drift Indicators
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Returns the count of Drift Indicators by the date. |
falcon_Free · Read-only | Read container drift indicator records by ID. |
falcon_Free · Read-only | Returns the total count of Drift indicators over a time period. |
falcon_Free · Read-only | Search container drift indicators and return the full records in one call, rather than searching for IDs and reading them separately. |
falcon_Free · Read-only | Search container drift indicators and return the matching IDs. |
Scanning Orchestrator
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create agentless scanning schedules. |
falcon_Pro · Destructive | Delete agentless scanning schedules. |
falcon_Free · Read-only | Search agentless scanning schedules and return the full schedule records in one call. |
falcon_Free · Read-only | Read agentless scanning schedules by ID. |
falcon_Free · Read-only | List the service types agentless scanning is allowed to scan. |
falcon_Free · Read-only | Search agentless scanning schedules and return the matching IDs. |
falcon_Pro · Destructive | Dispatch the scans defined by a schedule immediately, rather than waiting for the schedule to fire. |
falcon_Pro · Destructive | Update agentless scanning schedules. |
Serverless Exports
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Launch a serverless vulnerability export job. |
falcon_Free · Read-only | Search serverless vulnerability export jobs and return the matching job IDs. |
falcon_Free · Read-only | Read serverless vulnerability export jobs by ID. |
Serverless Vulnerabilities
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve all lambda vulnerabilities that match the given query and return in the SARIF format. |
Admission Control Policies
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Put an admission control policy into force over one or more further host groups. |
falcon_Pro · Write | Add one or more custom Rego rules to a named rule group in an admission control policy. |
falcon_Pro · Write | Create an admission control policy. |
falcon_Pro · Write | Create one or more rule groups and attach them to an existing admission control policy. |
falcon_Pro · Destructive | Delete an admission control policy. |
falcon_Pro · Destructive | Delete rule groups from an admission control policy. |
falcon_Free · Read-only | Read full admission control policy records by ID. |
falcon_Free · Read-only | Search admission control policies. |
falcon_Pro · Destructive | Remove one or more host groups from an admission control policy. |
falcon_Pro · Destructive | Delete one or more custom Rego rules from every rule group in an admission control policy. |
falcon_Pro · Destructive | Replace the labels and namespaces that a rule group inside an admission control policy selects on. |
falcon_Pro · Destructive | Change the evaluation order of the rule groups inside an admission control policy. |
falcon_Pro · Destructive | Update an admission control policy. |
falcon_Pro · Destructive | Change the order in which admission control policies are evaluated. |
falcon_Pro · Write | Update a rule group in an admission control policy: its name, description, deny-on-error setting, image assessment settings, default rule actions and custom rule actions. |
Container Alerts
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Count the container alerts matching the search criteria. |
falcon_Free · Read-only | Count container alerts broken down by severity. |
falcon_Free · Read-only | Search container alerts and return the full alert records in one call, rather than IDs to look up separately. |
Container Detections
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Search container runtime detections and return the full records in one call. |
falcon_Free · Read-only | Search image assessment detections and return the full records in one call. |
falcon_Free · Read-only | Read full image assessment detection records by ID. |
falcon_Free · Read-only | Count the image assessment detections matching the filter. |
falcon_Free · Read-only | Count image assessment detections broken down by severity. |
falcon_Free · Read-only | Count image assessment detections broken down by detection type. |
falcon_Free · Read-only | Search image assessment detections. |
Container Image Compliance
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get the compliance assessment totals for each Kubernetes cluster. |
falcon_Free · Read-only | Get the containers that failed compliance, grouped by the rule each one failed. |
falcon_Free · Read-only | Count the containers that failed compliance, grouped by severity level. |
falcon_Free · Read-only | Get the container images that failed compliance, grouped by the rule each one failed. |
falcon_Free · Read-only | Count the container images that failed compliance, grouped by severity level. |
falcon_Free · Read-only | Get the failed compliance rules for each Kubernetes cluster, grouped by severity level. |
falcon_Free · Read-only | Get the container images that have failed compliance rules, with each image failed-rule count grouped by severity. |
falcon_Free · Read-only | Count the failed compliance rules, grouped by severity level. |
falcon_Free · Read-only | Get the compliance assessment totals for each container image. |
falcon_Free · Read-only | Get the compliance assessment totals for each compliance rule. |
falcon_Free · Read-only | Get the compliance rules grouped by their pass or fail status. |
Container Images
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get the image assessment history over time. |
falcon_Free · Read-only | Count the container images matching the filter. |
falcon_Free · Read-only | Count container images grouped by base OS distribution. |
falcon_Free · Read-only | Count container images grouped by state. |
falcon_Free · Read-only | Read the base images registered for this customer, filtered by FQL. |
falcon_Free · Read-only | Get the container images carrying the most vulnerabilities, ranked highest first. |
falcon_Free · Read-only | Read full container image records matching the filter, in one call. |
falcon_Free · Read-only | Get a per-image summary of open issues: image assessment detections, runtime detections, policy results and vulnerabilities. |
falcon_Free · Read-only | Get a summary of the vulnerabilities affecting one container image. |
falcon_Pro · Write | Register one or more base images. |
falcon_Pro · Destructive | Delete base images by base image UUID. |
falcon_Free · Read-only | Read image assessment results for the container images matching the filter. |
falcon_Free · Read-only | Read container images for export, with the option to expand each image aggregated vulnerabilities and detections. |
Container Packages
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get the application packages carrying the most fixable vulnerabilities, ranked highest first. |
falcon_Free · Read-only | Get the packages used across the most container images, ranked highest first. |
falcon_Free · Read-only | Get the packages carrying the most vulnerabilities, ranked highest first. |
falcon_Free · Read-only | Read the packages matching the filter, in one call. |
falcon_Free · Read-only | Read packages for export. |
falcon_Free · Read-only | Read the packages matching the filter, in one call. |
falcon_Free · Read-only | Count the packages affected by zero-day vulnerabilities. |
Container Vulnerabilities
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Read the container vulnerabilities matching the filter. |
falcon_Free · Read-only | Read the vulnerability detail for one container image. |
falcon_Free · Read-only | Read vulnerability and package information for this customer. |
falcon_Free · Read-only | Get the vulnerabilities affecting the most container images, ranked highest first. |
falcon_Free · Read-only | Get the most recently published container vulnerabilities, newest first. |
falcon_Free · Read-only | Count the container vulnerabilities matching the filter. |
falcon_Free · Read-only | Count container vulnerabilities grouped by whether they are actively exploited. |
falcon_Free · Read-only | Count container vulnerabilities grouped by CrowdStrike severity rating (csp_rating). |
falcon_Free · Read-only | Count container vulnerabilities grouped by CVSS score. |
falcon_Free · Read-only | Count container vulnerabilities grouped by severity. |
Falcon Container
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Register a container registry connection so Falcon can pull and scan its images. |
falcon_Pro · Destructive | Delete container images by ID, together with their assessment results. |
falcon_Pro · Destructive | Delete a container registry connection by UUID. |
falcon_Free · Read-only | Read the registry credentials held for this customer container image registry integration. |
falcon_Free · Read-only | Get the image assessment scan report for an image, addressed by its image reference. |
falcon_Free · Read-only | Get the image assessment scan report for one scan, addressed by its scan UUID. |
falcon_Free · Read-only | Get the response headers for the image scan inventory POST without sending an inventory. |
falcon_Free · Read-only | Check whether a scanned image matches an image assessment policy. |
falcon_Pro · Destructive | Start an export job for a Container Security resource. |
falcon_Free · Read-only | Check a container image against the image prevention policies in force. |
falcon_Pro · Write | Post an image scan inventory. |
falcon_Free · Read-only | Search Container Security export jobs. |
falcon_Free · Read-only | Read full Container Security export job records by ID, including each job status. |
falcon_Free · Read-only | Read the known vulnerabilities for the container image supplied in the request body. |
falcon_Free · Read-only | Search the container registry connections registered for this customer, then pass the UUIDs to falcon_read_registry_entities_by_uuid to read the connection records. |
falcon_Free · Read-only | Read container registry connection records by UUID, up to 100 UUIDs per call. |
falcon_Pro · Destructive | Update a container registry connection, addressed by its UUID. |
Image Assessment Policies
| Tool | What it does |
|---|---|
falcon_Pro · Write | Create image assessment policy groups. |
falcon_Pro · Destructive | Delete an image assessment policy by UUID. |
falcon_Pro · Destructive | Delete image assessment policy groups. |
falcon_Pro · Write | Create image assessment policies. |
falcon_Pro · Destructive | Update image assessment policies. |
falcon_Pro · Destructive | Change the order in which image assessment policies are evaluated. |
falcon_Free · Read-only | Read all image assessment policies. |
falcon_Free · Read-only | Read the image assessment policy exclusions. |
falcon_Free · Read-only | Read the image assessment policy groups. |
falcon_Pro · Destructive | Update the image assessment policy exclusions. |
falcon_Pro · Destructive | Update image assessment policy groups. |
Kubernetes Container Compliance
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Returns cluster details along with aggregated assessment results organized by cluster, including pass/fail assessment counts for various asset types. |
falcon_Free · Read-only | Returns rule details along with aggregated assessment results organized by compliance rule, including pass/fail assessment counts. |
falcon_Free · Read-only | Provides aggregated compliance assessment metrics and rule status information, organized by asset type. |
falcon_Free · Read-only | Provides aggregated compliance assessment metrics and rule status information, organized by Kubernetes cluster type. |
falcon_Free · Read-only | Provides aggregated compliance assessment metrics and rule status information, organized by compliance framework. |
falcon_Free · Read-only | Retrieves the most non-compliant clusters, ranked in descending order based on the number of failed compliance rules across severity levels (critical, high, medium, and low). |
falcon_Free · Read-only | Retrieves the most non-compliant container images, ranked in descending order based on the number of failed assessments across severity levels (critical, high, medium, and low). |
falcon_Free · Read-only | Returns detailed compliance assessment results for container images, providing the information needed to identify compliance violations. |
falcon_Free · Read-only | Returns detailed compliance assessment results for kubernetes nodes, providing the information needed to identify compliance violations. |
falcon_Free · Read-only | Read compliance rule detail by rule ID, including the description, the remediation steps and the audit procedure. |
Kubernetes Protection
| Tool | What it does |
|---|---|
falcon_Pro · Write | Register an AWS account with Kubernetes Protection and generate its installation script. |
falcon_Pro · Write | Register an Azure subscription with Kubernetes Protection. |
falcon_Pro · Destructive | Remove AWS accounts from Kubernetes Protection. |
falcon_Pro · Destructive | Remove an Azure subscription from Kubernetes Protection. |
falcon_Free · Read-only | Retrieve containers by container_runtime_version. |
falcon_Free · Read-only | Retrieve containers count affected by zero day vulnerabilities. |
falcon_Free · Read-only | List the AWS accounts registered with Kubernetes Protection. |
falcon_Free · Read-only | Get the installation script to run for a given Azure tenant ID and subscription IDs. |
falcon_Free · Read-only | Read the Azure tenant configuration held by Kubernetes Protection. |
falcon_Free · Read-only | List the Azure subscriptions and tenants known to Kubernetes Protection. |
falcon_Free · Read-only | List the Kubernetes clusters acknowledged by Kubernetes Protection. |
falcon_Free · Read-only | List the provisioned cloud accounts together with the Kubernetes clusters known inside them. |
falcon_Free · Read-only | Get a sample Helm values.yaml file to install alongside the Kubernetes Protection agent Helm chart. |
falcon_Free · Read-only | List the cloud locations acknowledged by Kubernetes Protection. |
falcon_Free · Read-only | Get the static bash scripts used during Kubernetes Protection registration. |
falcon_Free · Read-only | Group the containers by Managed. |
falcon_Free · Read-only | List the Azure subscriptions registered with Kubernetes Protection. |
falcon_Pro · Write | Record the Azure application client ID against a tenant ID in Kubernetes Protection. |
falcon_Free · Read-only | Get aggregate query result for pods. |
falcon_Free · Read-only | Search Kubernetes indicators of misconfiguration (IOMs) with the criteria in the request body. |
falcon_Free · Read-only | Read full Kubernetes cluster records matching the filter, in one call. |
falcon_Free · Read-only | Read full Kubernetes cluster records, in one call. |
falcon_Free · Read-only | Retrieve cluster counts. |
falcon_Free · Read-only | Retrieve cluster enrichment data. |
falcon_Free · Read-only | Retrieve clusters by date range counts. |
falcon_Free · Read-only | Bucket clusters by kubernetes version. |
falcon_Free · Read-only | Bucket clusters by status. |
falcon_Free · Read-only | Read full container records matching the filter, in one call. |
falcon_Free · Read-only | Retrieve container counts. |
falcon_Free · Read-only | Retrieves a list with the top container image registries. |
falcon_Free · Read-only | Retrieve container enrichment data. |
falcon_Free · Read-only | Retrieve count of image assessment detections on running containers over a period of time. |
falcon_Free · Read-only | Bucket container by image-digest. |
falcon_Free · Read-only | Retrieve count of image states running on containers. |
falcon_Free · Read-only | Retrieve container vulnerabilities by severity counts. |
falcon_Free · Read-only | Retrieve containers by date range counts. |
falcon_Free · Read-only | Bucket containers by agent type and calculate sensor coverage. |
falcon_Free · Read-only | Read full Kubernetes deployment records matching the filter, in one call. |
falcon_Free · Read-only | Retrieve deployment counts. |
falcon_Free · Read-only | Retrieve deployment enrichment data. |
falcon_Free · Read-only | Retrieve deployments by date range counts. |
falcon_Free · Read-only | Retrieve count of distinct images running on containers. |
falcon_Free · Read-only | Returns the count of Kubernetes IOMs by the date. |
falcon_Free · Read-only | Returns the total count of Kubernetes IOMs over the past seven days. |
falcon_Free · Read-only | Read full Kubernetes indicator of misconfiguration (IOM) records by ID. |
falcon_Free · Read-only | Retrieve namespace counts. |
falcon_Free · Read-only | Retrieve namespaces by date range counts. |
falcon_Free · Read-only | Read full Kubernetes node records matching the filter, in one call. |
falcon_Free · Read-only | Retrieve node counts. |
falcon_Free · Read-only | Retrieve node enrichment data. |
falcon_Free · Read-only | Bucket nodes by cloud providers. |
falcon_Free · Read-only | Bucket nodes by their container engine version. |
falcon_Free · Read-only | Retrieve nodes by date range counts. |
falcon_Free · Read-only | Read full Kubernetes pod records matching the filter, in one call. |
falcon_Free · Read-only | Retrieve pod counts. |
falcon_Free · Read-only | Retrieve pod enrichment data. |
falcon_Free · Read-only | Retrieve pods by date range counts. |
falcon_Free · Read-only | Read the images that are running on containers right now. |
falcon_Free · Read-only | Retrieve count of vulnerable images running on containers. |
falcon_Pro · Destructive | Mint a new API key for the docker registry integrations. |
falcon_Free · Read-only | Search Kubernetes indicators of misconfiguration (IOMs) and return the full records in one call. |
falcon_Free · Read-only | Search Kubernetes indicators of misconfiguration (IOMs). |
falcon_Pro · Destructive | Start a dry run or a full scan of the customer Kubernetes footprint. |
falcon_Pro · Write | Update a registered AWS account in Kubernetes Protection from the query parameters supplied. |
Unidentified Containers
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Count unidentified containers by date over the last 7 days. |
falcon_Free · Read-only | Count the unidentified containers seen over a time period. |
falcon_Free · Read-only | Search unidentified containers and return the full records in one call, rather than IDs to look up separately. |
Access Scopes
| Tool | What it does |
|---|---|
falcon_Free · Read-only | List Access Scopes By ID. |
falcon_Free · Read-only | Query Access Scopes and returns IDs. |
API Clients
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Create new API Client. |
falcon_Pro · Destructive | Delete existing API Client(s) based on API Client ID(s) provided as request parameter(s) 'ids'. |
falcon_Free · Read-only | Get all available scopes for customer. |
falcon_Free · Read-only | Get All API client ID(s) for customer. |
falcon_Free · Read-only | Get API Client(s) based on API Client ID(s) provided as request parameter(s) 'ids'. |
falcon_Pro · Destructive | Reset existing API Client(s)'s secret based on API Client ID(s) provided as request parameter(s) 'ids'. |
falcon_Pro · Destructive | Update existing API Client based on API Client ID provided as request parameter 'ids'. |
API Integrations
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Execute a command. |
falcon_Pro · Destructive | Execute a command and proxy the response directly. |
falcon_Free · Read-only | Queries for config resources and returns details. |
Case Management
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get access tag aggregates. |
falcon_Free · Read-only | Get file details aggregates as specified via json in the request body. |
falcon_Free · Read-only | Get notification groups aggregations. |
falcon_Free · Read-only | Get notification groups aggregations. |
falcon_Free · Read-only | Get SLA aggregations. |
falcon_Free · Read-only | Get templates aggregations. |
falcon_Free · Read-only | Query file details. |
falcon_Free · Read-only | Get access tags. |
falcon_Pro · Write | Adds the given list of alert evidence to the specified case. |
falcon_Pro · Destructive | Removes the specified tags from the specified case. |
falcon_Pro · Write | Adds the given list of tags to the specified case. |
falcon_Pro · Write | Updates given fields on the specified case. |
falcon_Free · Read-only | Retrieves all Cases given their IDs. |
falcon_Pro · Destructive | Creates the given Case. |
falcon_Pro · Write | Adds the given list of event evidence to the specified case. |
falcon_Free · Read-only | Get fields by ID. |
falcon_Free · Read-only | Get file details by id. |
falcon_Pro · Write | Update file details. |
falcon_Pro · Destructive | Delete file details by id. |
falcon_Pro · Write | Upload file for case. |
falcon_Free · Read-only | gets metadata for a file via RTR without retrieving it. |
falcon_Pro · Write | Merges a source case into a destination case. |
falcon_Pro · Destructive | Delete notification groups by ID. |
falcon_Pro · Destructive | Delete notification groups by ID. |
falcon_Free · Read-only | Get notification groups by ID. |
falcon_Free · Read-only | Get notification groups by ID. |
falcon_Pro · Write | Update notification group. |
falcon_Pro · Write | Update notification group. |
falcon_Pro · Write | Create notification group. |
falcon_Pro · Write | Create notification group. |
falcon_Pro · Destructive | retrieves a file from host using RTR and adds it to a case. |
falcon_Pro · Write | RetrieveRecentRTRFile retrieves a recently fetched RTR file and adds it to a case. |
falcon_Pro · Destructive | Delete SLAs. |
falcon_Free · Read-only | Get SLAs by ID. |
falcon_Pro · Write | Update SLA. |
falcon_Pro · Write | Create SLA. |
falcon_Free · Read-only | Get template snapshots. |
falcon_Pro · Destructive | Delete templates. |
falcon_Free · Read-only | Export templates to files in a zip archive. |
falcon_Free · Read-only | Get templates by ID. |
falcon_Pro · Write | Import a template from a file. |
falcon_Pro · Write | Update template. |
falcon_Pro · Write | Create template. |
falcon_Free · Read-only | Query access tags. |
falcon_Free · Read-only | Retrieves all Cases IDs that match a given query. |
falcon_Free · Read-only | Query fields. |
falcon_Free · Read-only | Query for ids of file details. |
falcon_Free · Read-only | Query notification groups. |
falcon_Free · Read-only | Query notification groups. |
falcon_Free · Read-only | Query SLAs. |
falcon_Free · Read-only | Query template snapshots. |
falcon_Free · Read-only | Query templates. |
Federated Connections
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Delete configuration for a federated connection. |
falcon_Pro · Write | Update configuration for a federated connection. |
falcon_Pro · Write | Create configuration for a federated connection. |
Message Center
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Retrieve aggregate case values based on the matched filter. |
falcon_Pro · Destructive | Add an activity to case. |
falcon_Pro · Destructive | Upload an attachment for the case. |
falcon_Pro · Destructive | create a new case. |
falcon_Free · Read-only | Retrieve activities for given id's. |
falcon_Free · Read-only | Retrieve message center cases. |
falcon_Free · Read-only | Retrieve activities id's for a case. |
falcon_Free · Read-only | Retrieve case id's that match the provided filter criteria. |
Flight Control (MSSP)
| Tool | What it does |
|---|---|
falcon_Pro · Destructive | Add new CID group member. |
falcon_Pro · Destructive | Create a link between user group and CID group, with zero or more additional roles. |
falcon_Pro · Destructive | Add new user group member. |
falcon_Pro · Destructive | Create new CID groups. |
falcon_Pro · Destructive | Create new user groups. |
falcon_Pro · Destructive | Delete CID group members. |
falcon_Pro · Destructive | Delete CID groups by ID. |
falcon_Pro · Destructive | Delete user group members entry. |
falcon_Pro · Destructive | Delete user groups by ID. |
falcon_Pro · Destructive | Delete links or additional roles between user groups and CID groups. |
falcon_Free · Read-only | Get link to child customer by child CID(s). |
falcon_Free · Read-only | Get link to child customer by child CID(s). |
falcon_Free · Read-only | Get CID Groups by ID. |
falcon_Free · Read-only | Get CID Groups by ID. |
falcon_Free · Read-only | Get CID group members by CID Group ID. |
falcon_Free · Read-only | Get CID group members by CID Group ID. |
falcon_Free · Read-only | Get link between user group and CID group by ID. |
falcon_Free · Read-only | Get user group members by user group ID. |
falcon_Free · Read-only | Get user group members by user group ID. |
falcon_Free · Read-only | Get user groups by ID. |
falcon_Free · Read-only | Get user groups by ID. |
falcon_Free · Read-only | Query for customers linked as children. |
falcon_Free · Read-only | Query a CID groups members by associated CID. |
falcon_Free · Read-only | Query CID groups. |
falcon_Free · Read-only | Query links between user groups and CID groups. |
falcon_Free · Read-only | Query user group member by user UUID. |
falcon_Free · Read-only | Query user groups. |
falcon_Pro · Destructive | Update existing CID groups. |
falcon_Pro · Destructive | Update existing user group(s). |
Next-Gen SIEM
| Tool | What it does |
|---|---|
falcon_Pro · Write | Add multiple labels to a single dashboard. |
falcon_Pro · Write | Add multiple labels to a single file. |
falcon_Pro · Write | Add multiple labels to a saved query. |
falcon_Pro · Write | Add labels to multiple dashboards (max 100 items, non-transactional). |
falcon_Pro · Write | Add labels to multiple lookup files (max 100 items, non-transactional). |
falcon_Pro · Write | Add labels to multiple saved queries (max 100 items, non-transactional). |
falcon_Pro · Write | Create Multiple Dashboards from YAML Templates. |
falcon_Pro · Write | Create Multiple Lookup Files. |
falcon_Pro · Write | Create Multiple Saved Queries from LogScale YAML Templates. |
falcon_Free · Read-only | Retrieve Multiple Lookup Files by Filenames in NGSIEM. |
falcon_Pro · Write | Installs multiple CrowdStrike-managed out-of-the-box (OOTB) parsers into the customer's repository in a single operation. |
falcon_Pro · Destructive | Remove labels from multiple dashboards (max 100 items, non-transactional). |
falcon_Pro · Destructive | Remove labels from multiple lookup files (max 100 items, non-transactional). |
falcon_Pro · Destructive | Remove labels from multiple saved queries (max 100 items, non-transactional). |
falcon_Pro · Write | Replace all labels on multiple dashboards (max 100 items, non-transactional). |
falcon_Pro · Write | Update Multiple Dashboards from YAML Templates. |
falcon_Pro · Write | Replace all labels on multiple lookup files (max 100 items, non-transactional). |
falcon_Pro · Write | Update Multiple Lookup Files. |
falcon_Pro · Write | Update Multiple Saved Queries from LogScale YAML Templates. |
falcon_Pro · Write | Replace all labels on multiple saved queries (max 100 items, non-transactional). |
falcon_Pro · Write | Clone an existing parser with a new name. |
falcon_Pro · Write | Create Dashboard from LogScale YAML Template in NGSIEM. |
falcon_Pro · Write | Create Lookup File in NGSIEM. |
falcon_Pro · Write | Create a Parser extension in NGSIEM for the provided base parser. |
falcon_Pro · Write | Create Parser from LogScale YAML Template in NGSIEM. |
falcon_Pro · Write | Create Saved Query from LogScale YAML Template in NGSIEM. |
falcon_Pro · Destructive | Delete Dashboard in NGSIEM. |
falcon_Pro · Destructive | Delete Lookup File in NGSIEM. |
falcon_Pro · Destructive | Delete Parser in NGSIEM. |
falcon_Pro · Destructive | Delete Saved Query in NGSIEM. |
falcon_Pro · Write | Create a new configuration for a data connector. |
falcon_Pro · Write | Create a new data connection. |
falcon_Pro · Destructive | Delete data connection config. |
falcon_Pro · Destructive | Delete a data connection. |
falcon_Free · Read-only | Get data connection by ID. |
falcon_Free · Read-only | Get data connection provisioning status. |
falcon_Free · Read-only | Get Ingest token for data connection. |
falcon_Free · Read-only | List configurations for a data connector. |
falcon_Free · Read-only | List and search data connections. |
falcon_Free · Read-only | List available data connectors. |
falcon_Pro · Write | Patch configurations for a data connector. |
falcon_Pro · Destructive | DESTRUCTIVE: rotating the ingest token invalidates the one every collector on this data connection is configured with, so ingestion stops until each is updated with the new token. |
falcon_Pro · Write | Update a data connection. |
falcon_Pro · Write | Update data connection status. |
falcon_Free · Read-only | Retrieve Dashboard(s) in NGSIEM as LogScale YAML Template. |
falcon_Free · Read-only | Retrieve Lookup File in NGSIEM. |
falcon_Free · Read-only | Download lookup file in package from NGSIEM. |
falcon_Free · Read-only | Download lookup file in namespaced package from NGSIEM. |
falcon_Free · Read-only | Download lookup file from NGSIEM. |
falcon_Free · Read-only | Retrieve Parser in NGSIEM as LogScale YAML Template. |
falcon_Free · Read-only | Retrieve Saved Quer(ies) in NGSIEM as LogScale YAML Template. |
falcon_Free · Read-only | Get status of search. |
falcon_Pro · Destructive | Installs a CrowdStrike-managed out-of-the-box (OOTB) parser into the customer's repository. |
falcon_Free · Read-only | List Dashboards in NGSIEM with Pagination and Filtering. |
falcon_Free · Read-only | List Lookup Files in NGSIEM with Pagination and Filtering. |
falcon_Free · Read-only | List Parsers in NGSIEM. |
falcon_Free · Read-only | List Saved Queries in NGSIEM with Pagination and Filtering. |
falcon_Pro · Destructive | Remove multiple labels from a single dashboard. |
falcon_Pro · Destructive | Remove multiple labels from a single file. |
falcon_Pro · Destructive | Remove multiple labels from a saved query. |
falcon_Pro · Destructive | Initiate search. |
falcon_Pro · Destructive | Stop search. |
falcon_Pro · Write | Test Parser from LogScale YAML Template in NGSIEM. |
falcon_Pro · Write | Update Dashboard from LogScale YAML Template in NGSIEM. |
falcon_Pro · Destructive | Replace all labels on a single dashboard. |
falcon_Pro · Destructive | Replace all labels on a single file. |
falcon_Pro · Write | Update an entire Lookup File in NGSIEM. |
falcon_Pro · Write | Update entries in an existing Lookup File in NGSIEM. |
falcon_Pro · Write | Update an NGSIEM parser in place. |
falcon_Pro · Destructive | Updates a parser auto update policy - 'on' enables auto-updates, 'off' disables them. |
falcon_Pro · Write | Update an existing Parser extension in NGSIEM. |
falcon_Pro · Write | Update Parser in NGSIEM from YAML Template. |
falcon_Pro · Write | Update Saved Query from LogScale YAML Template in NGSIEM. |
falcon_Pro · Destructive | Replace all labels on a single saved query. |
falcon_Pro · Write | Upload file to NGSIEM. |
User Management
| Tool | What it does |
|---|---|
falcon_Free · Read-only | Get host aggregates as specified via json in request body. |
falcon_Free · Read-only | Get User Grant(s). |
falcon_Pro · Destructive | Create a new user. |
falcon_Pro · Destructive | Delete a user permanently. |
falcon_Free · Read-only | Get info about a role. |
falcon_Free · Read-only | Get info about a role. |
falcon_Free · Read-only | Show role IDs for all roles available in your customer account. |
falcon_Free · Read-only | List user IDs for all users in your customer account. |
falcon_Free · Read-only | Get info about users including their name, UID and CID by providing user UUIDs. |
falcon_Pro · Destructive | Modify an existing user's first or last name. |
falcon_Pro · Destructive | Apply actions to one or more User. |
falcon_Pro · Destructive | Grant or Revoke one or more role(s) to a user against a CID. |
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team