-
Notifications
You must be signed in to change notification settings - Fork 172
Custom IOA
| API Function | Description |
|---|---|
| get_patterns | Get pattern severities by ID. |
| get_platformsMixin0 | Get platforms by ID. |
| get_rule_groupsMixin0 | Get rule groups by ID. |
| create_rule_groupMixin0 | Create a rule group for a platform with a name and an optional description. Returns the rule group. |
| delete_rule_groupsMixin0 | Delete rule groups by ID. |
| update_rule_groupMixin0 | Update a rule group. The following properties can be modified: name, description, enabled. |
| get_rule_types | Get rule types by ID. |
| get_rules_get | Get rules by ID and optionally version in the following format: ID[:version]. |
| get_rulesMixin0 | Get rules by ID and optionally version in the following format: ID[:version]. The max number of IDs is constrained by URL size. |
| create_rule | Create a rule within a rule group. Returns the rule. |
| delete_rules | Delete rules from a rule group by ID. |
| update_rules | Update rules within a rule group. Return the updated rules. |
| validate | Validates field values and checks for matches if a test string is provided. |
| query_patterns | Get all pattern severity IDs. |
| query_platformsMixin0 | Get all platform IDs. |
| query_rule_groups_full | Find all rule groups matching the query with optional filter. |
| query_rule_groupsMixin0 | Finds all rule group IDs matching the query with optional filter. |
| query_rule_types | Get all rule type IDs. |
| query_rulesMixin0 | Finds all rule IDs matching the query with optional filter. |
Get pattern severities by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
IDS = 'ID1,ID2,ID3'
response = falcon.get_patterns(ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
IDS = 'ID1,ID2,ID3'
response = falcon.command('get-patterns', ids=IDS)
print(response)
falcon.deauthenticate()Get platforms by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
IDS = 'ID1,ID2,ID3'
response = falcon.get_platformsMixin0(ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
IDS = 'ID1,ID2,ID3'
response = falcon.command('get-platformsMixin0', ids=IDS)
print(response)
falcon.deauthenticate()Get rule groups by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
IDS = 'ID1,ID2,ID3'
response = falcon.get_rule_groupsMixin0(ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
IDS = 'ID1,ID2,ID3'
response = falcon.command('get-rule-groupsMixin0', ids=IDS)
print(response)
falcon.deauthenticate()Create a rule group for a platform with a name and an optional description. Returns the rule group.
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.create_rule_groupMixin0(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('create-rule-groupMixin0', body=BODY)
print(response)
falcon.deauthenticate()Delete rule groups by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| comment | query | string | Explains why the entity is being deleted | |
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'comment': 'string'
}
IDS = 'ID1,ID2,ID3'
response = falcon.delete_rule_groupsMixin0(parameters=PARAMS, ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'comment': 'string'
}
IDS = 'ID1,ID2,ID3'
response = falcon.command('delete-rule-groupsMixin0', parameters=PARAMS, ids=IDS)
print(response)
falcon.deauthenticate()Update a rule group. The following properties can be modified: name, description, enabled.
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.update_rule_groupMixin0(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('update-rule-groupMixin0', body=BODY)
print(response)
falcon.deauthenticate()Get rule types by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
IDS = 'ID1,ID2,ID3'
response = falcon.get_rule_types(ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
IDS = 'ID1,ID2,ID3'
response = falcon.command('get-rule-types', ids=IDS)
print(response)
falcon.deauthenticate()Get rules by ID and optionally version in the following format: ID[:version].
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string | The "ids" field contains a list of the rules to retrieve. |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.get_rules_get(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('get-rules-get', body=BODY)
print(response)
falcon.deauthenticate()Get rules by ID and optionally version in the following format: ID[:version]. The max number of IDs is constrained by URL size.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
IDS = 'ID1,ID2,ID3'
response = falcon.get_rulesMixin0(ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
IDS = 'ID1,ID2,ID3'
response = falcon.command('get-rulesMixin0', ids=IDS)
print(response)
falcon.deauthenticate()Create a rule within a rule group. Returns the rule.
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.create_rule(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('create-rule', body=BODY)
print(response)
falcon.deauthenticate()Delete rules from a rule group by ID.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | rule_group_id | query | string | The parent rule group |
| comment | query | string | Explains why the entity is being deleted | |
| ✅ | ids | query | array (string) | The IDs of the entities |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'rule_group_id': 'string',
'comment': 'string'
}
IDS = 'ID1,ID2,ID3'
response = falcon.delete_rules(parameters=PARAMS, ids=IDS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'rule_group_id': 'string',
'comment': 'string'
}
IDS = 'ID1,ID2,ID3'
response = falcon.command('delete-rules', parameters=PARAMS, ids=IDS)
print(response)
falcon.deauthenticate()Update rules within a rule group. Return the updated rules.
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.update_rules(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('update-rules', body=BODY)
print(response)
falcon.deauthenticate()Validates field values and checks for matches if a test string is provided.
- Consumes: application/json
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| ✅ | body | body | string |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.validate(body=BODY)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
BODY = {
'Body Payload': 'See body description above'
}
response = falcon.command('validate', body=BODY)
print(response)
falcon.deauthenticate()Get all pattern severity IDs.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.query_patterns(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.command('query-patterns', parameters=PARAMS)
print(response)
falcon.deauthenticate()Get all platform IDs.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.query_platformsMixin0(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.command('query-platformsMixin0', parameters=PARAMS)
print(response)
falcon.deauthenticate()Find all rule groups matching the query with optional filter.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| sort | query | string | Possible order by fields: {created_by, created_on, modified_by, modified_on, enabled, name, description} | |
| filter | query | string | FQL query specifying the filter parameters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as '2010-05-15T14:55:21.892315096Z'. | |
| q | query | string | Match query criteria, which includes all the filter string fields | |
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.query_rule_groups_full(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.command('query-rule-groups-full', parameters=PARAMS)
print(response)
falcon.deauthenticate()Finds all rule group IDs matching the query with optional filter.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| sort | query | string | Possible order by fields: {created_by, created_on, modified_by, modified_on, enabled, name, description} | |
| filter | query | string | FQL query specifying the filter parameters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as '2010-05-15T14:55:21.892315096Z'. | |
| q | query | string | Match query criteria, which includes all the filter string fields | |
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.query_rule_groupsMixin0(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.command('query-rule-groupsMixin0', parameters=PARAMS)
print(response)
falcon.deauthenticate()Get all rule type IDs.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.query_rule_types(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'offset': 'string',
'limit': integer
}
response = falcon.command('query-rule-types', parameters=PARAMS)
print(response)
falcon.deauthenticate()Finds all rule IDs matching the query with optional filter.
- Produces: application/json
| Required | Name | Type | Datatype | Description |
|---|---|---|---|---|
| sort | query | string | Possible order by fields: {rules.ruletype_name, rules.enabled, rules.created_by, rules.current_version.name, rules.current_version.modified_by, rules.created_on, rules.current_version.description, rules.current_version.pattern_severity, rules.current_version.action_label, rules.current_version.modified_on} | |
| filter | query | string | FQL query specifying the filter parameters. Filter term criteria: [enabled platform name description rules.action_label rules.name rules.description rules.pattern_severity rules.ruletype_name rules.enabled]. Filter range criteria: created_on, modified_on; use any common date format, such as '2010-05-15T14:55:21.892315096Z'. | |
| q | query | string | Match query criteria, which includes all the filter string fields | |
| offset | query | string | Starting index of overall result set from which to return IDs | |
| limit | query | integer | Number of IDs to return |
from falconpy import custom_ioa as FalconIOA
falcon = FalconIOA.Custom_IOA(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
})
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.query_rulesMixin0(parameters=PARAMS)
print(response)from falconpy import api_complete as FalconSDK
falcon = FalconSDK.APIHarness(creds={
'client_id': falcon_client_id,
'client_secret': falcon_client_secret
}
)
PARAMS = {
'sort': 'string',
'filter': 'string',
'q': 'string',
'offset': 'string',
'limit': integer
}
response = falcon.command('query-rulesMixin0', parameters=PARAMS)
print(response)
falcon.deauthenticate()
- Home
- Discussions Board
- Glossary of Terms
- Installation, Upgrades and Removal
- Samples Collection
- Using FalconPy
- API Operations
-
Service Collections
- Admission Control Policies
- Alerts
- API Integrations
- ASPM
- CAO Hunting
- Case Management
- Certificate Based Exclusions
- Cloud AWS Registration
- Cloud Azure Registration
- Cloud GCP Registration
- Cloud OCI Registration
- Cloud Policies
- Cloud Connect AWS (deprecated)
- Cloud Security Assets
- Cloud Security
- Cloud Security Compliance
- Cloud Security Detections
- Cloud Snapshots
- Configuration Assessment
- Configuration Assessment Evaluation Logic
- Container Alerts
- Container Detections
- Container Image Compliance
- Container Images
- Container Packages
- Container Vulnerabilities
- Content Update Policies
- Correlation Rules
- Correlation Rules Admin
- CSPM Registration
- Custom IOAs
- Custom Storage
- D4C Registration (deprecated)
- Data Protection Configuration
- DataScanner (deprecated)
- Delivery Settings
- Deployments
- Detects (deprecated)
- Device Content
- Device Control Policies
- Discover
- Downloads
- Drift Indicators
- Event Streams
- Exposure Management
- FaaS Execution
- Falcon Complete Dashboard
- Falcon Container
- Falcon Intelligence Sandbox
- FDR
- FileVantage
- Firewall Management
- Firewall Policies
- Foundry LogScale
- Host Group
- Host Migration
- Hosts
- Identity Protection
- Image Assessment Policies
- Incidents
- Installation Tokens
- Intel
- Intelligence Feeds
- Intelligence Indicator Graph
- IOA Exclusions
- IOC
- IOCs (deprecated)
- IT Automation
- Kubernetes Container Compliance
- Kubernetes Protection
- MalQuery
- Message Center
- ML Exclusions
- Mobile Enrollment
- MSSP (Flight Control)
- NGSIEM
- OAuth2
- ODS (On Demand Scan)
- Prevention Policy
- Quarantine
- Quick Scan
- Quick Scan Pro
- Real Time Response
- Real Time Response Admin
- Real Time Response Audit
- Recon
- Report Executions
- Response Policies
- Sample Uploads
- SaaS Security
- Scheduled Reports
- Sensor Download
- Sensor Update Policy
- Sensor Usage
- Sensor Visibility Exclusions
- Serverless Exports
- Serverless Vulnerabilities
- Spotlight Evaluation Logic
- Spotlight Vulnerabilities
- Spotlight Vulnerability Metadata
- Tailored Intelligence
- ThreatGraph
- Unidentified Containers
- User Management
- Workflows
- Zero Trust Assessment
- Documentation Support
-
CrowdStrike SDKs
- Crimson Falcon - Ruby
- FalconPy - Python 3
- FalconJS - Javascript
- goFalcon - Go
- PSFalcon - Powershell
- Rusty Falcon - Rust
