Skip to content

Get FalconIocProcess

bk-cs edited this page Oct 31, 2022 · 20 revisions

Get-FalconIocProcess

SYNOPSIS

Search for processes involving a custom indicator on a specific host

DESCRIPTION

Requires 'IOCs: Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Id String[] X Process identifier
Type String domain
ipv4
ipv6
md5
sha256
Indicator type
Value String Indicator value
HostId String X Host identifier
Limit String 1 100 Maximum number of results per request
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved

SYNTAX

Get-FalconIocProcess [-Type] <String> [-Value] <String> [-HostId] <String> [[-Limit] <String>] [-Offset <Int32>] [-Detailed] [-All] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIocProcess -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

SDK Reference

falconpy

ProcessesRanOn
entities_processes

USAGE

Finding process IDs of an IOC found on a host

Get-FalconIocProcess -Type <string> -Value <string> -HostId <id> [-Detailed]

Getting process details

Get-FalconIocProcess -Id <id>, <id>

2022-10-31: PSFalcon v2.2.3

Clone this wiki locally