Skip to content

Get FalconIndicator

bk-cs edited this page Apr 28, 2023 · 23 revisions

Get-FalconIndicator

SYNOPSIS

Search for intelligence indicators

DESCRIPTION

Requires 'Indicators (Falcon Intelligence): Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Indicator identifier X X
Filter String Falcon Query Language expression to limit results

actors
deleted
domain_types
id
indicator
ip_address_types
kill_chains
labels
labels.name
last_updated
malicious_confidence
malware_families
published_date
reports
targets
threat_types
type
vulnerabilities
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results id|asc
id|desc
indicator|asc
indicator|desc
type|asc
type|desc
published_date|asc
published_date|desc
last_updated|asc
last_updated|desc
_marker|asc
_marker|desc
Limit Int32 Maximum number of results per request 1 5000
IncludeDeleted Boolean Include previously deleted indicators
IncludeRelation Boolean Include related indicators
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconIndicator [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [[-IncludeDeleted] <Boolean>] [[-IncludeRelation] <Boolean>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIndicator -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIndicator [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [[-IncludeDeleted] <Boolean>] [[-IncludeRelation] <Boolean>] [-Offset <Int32>] -Detailed [-All] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /intel/combined/indicators/v1
GET /intel/queries/indicators/v1
POST /intel/entities/indicators/GET/v1

falconpy

QueryIntelIndicatorIds
GetIntelIndicatorEntities
QueryIntelIndicatorEntities

USAGE

Search for indicator IDs

Get-FalconIndicator -Filter "type:'domain'" [-All]

Get indicators by ID

Get-FalconIndicator -Id <id>, <id>

Search for detailed indicator information

Get-FalconIndicator -Filter "last_updated:>=1427846400" -Sort "last_updated|asc" -Detailed [-All]

2023-04-25: PSFalcon v2.2.5

Clone this wiki locally