-
Notifications
You must be signed in to change notification settings - Fork 69
Get FalconCloudIoa
bk-cs edited this page Sep 3, 2024
·
1 revision
Search for Falcon Cloud Security Indicators of Attack
Requires 'CSPM registration: Read'.
Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
---|---|---|---|---|---|---|---|
CloudPlatform | String | Cloud platform |
aws azure
|
||||
AccountId | String | Cloud account identifier | X | ||||
AwsAccountId | String | AWS account identifier | X | ||||
AzureSubscriptionId | String | Azure subscription identifier | X | ||||
AzureTenantId | String | Azure tenant identifier | X | ||||
ResourceId | String[] | Resource identifier | |||||
ResourceUuid | String[] | Resource UUID | |||||
Severity | String | Indicator of Attack severity |
High Medium Informational
|
||||
Service | String | Cloud service |
ACM ACR Any App Engine AppService BigQuery Cloud Load Balancing Cloud Logging Cloud SQL Cloud Storage CloudFormation CloudTrail CloudWatch Logs Cloudfront Compute Engine Config Disk DynamoDB EBS EC2 ECR EFS EKS ELB EMR Elasticache GuardDuty IAM Identity KMS KeyVault Kinesis Kubernetes Lambda LoadBalancer Monitor NLB/ALB NetworkSecurityGroup PostgreSQL RDS Redshift S3 SES SNS SQLDatabase SQLServer SQS SSM Serverless Application Repository StorageAccount Subscriptions VPC VirtualMachine VirtualNetwork
|
||||
State | String | Indicator of Attack state |
open closed
|
||||
Since | String | Filter events using a duration string (e.g. 24h) | |||||
DateTimeSince | String | Include results that occur after a specific date and time (RFC3339) | |||||
Limit | Int32 | Maximum number of results per request | 1 |
1000 |
|||
NextToken | String | Pagination token to retrieve the next set of results | |||||
All | Switch | Repeat requests until all available results are retrieved | |||||
Total | Switch | Display total result count instead of results |
Get-FalconCloudIoa [-CloudPlatform] <String> [[-AccountId] <String>] [[-AwsAccountId] <String>] [[-AzureSubscriptionId] <String>] [[-AzureTenantId] <String>] [[-ResourceId] <String[]>] [[-ResourceUuid] <String[]>] [[-Severity] <String>] [[-Service] <String>] [[-State] <String>] [[-Since] <String>] [[-DateTimeSince] <String>] [[-Limit] <Int32>] [-NextToken <String>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
GET /detects/entities/ioa/v1
2024-09-03: PSFalcon v2.2.7
- Using PSFalcon
-
Commands and Permissions
- Configuration Import/Export
- Container Security
- Detection and Prevention Policies
- Discover for Cloud and Containers
- Discover
- Event Streams
- Falcon Complete Dashboards
- Falcon Complete Message Center
- Falcon Data Replicator
- Falcon Intelligence
- Falcon Intelligence Recon
- Falcon OverWatch Dashboards
- Falcon Sandbox
- FileVantage
- Firewall Management
- Flight Control
- Horizon
- Host and Host Group Management
- Identity Protection
- Image Assessment
- Incident and Detection Monitoring
- Installation Tokens
- Kubernetes Protection
- MalQuery
- Mobile Host Enrollment
- On-Demand Scanning
- Quarantine
- Real-time Response
- Real-time Response Policy
- Scheduled Reports and Searches
- Sensor Download
- Sensor Update Policy
- Spotlight
- Tailored Intelligence
- Third-party ingestion
- USB Device Control Policy
- Users and Roles
- Zero Trust Assessment
- Examples
-
CrowdStrike SDKs
- PSFalcon - PowerShell
- FalconPy - Python 3
- goFalcon - Go
- Rusty Falcon - Rust