Skip to content

Get FalconVulnerability

bk-cs edited this page Dec 29, 2022 · 26 revisions

Get-FalconVulnerability

SYNOPSIS

Search for Falcon Spotlight vulnerabilities

DESCRIPTION

Requires 'Spotlight Vulnerabilities: Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Id String[] X X Vulnerability identifier
Filter String Falcon Query Language expression to limit results

aid
apps_remediation
closed_timestamp
created_timestamp
cve.exploit_status
cve.exprt_rating
cve.id
cve.is_cisa_kev
cve.remediation_level
cve.severity
host_info.groups
host_info.platform_name
host_info.product_type_desc
host_info.tags
last_seen_within
status
suppression_info.is_suppressed
suppression_info.reason
updated_timestamp
Facet String[] cve
evaluation_logic
host_info
remediation
Include additional properties
Sort String created_timestamp.asc
created_timestamp.desc
closed_timestamp.asc
closed_timestamp.desc
updated_timestamp.asc
updated_timestamp.desc
Property and direction to sort results
Limit Int32 1 400 Maximum number of results per request
After String Pagination token to retrieve the next set of results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconVulnerability [-Filter] <String> [[-Sort] <String>] [[-Limit] <Int32>] [-After <String>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconVulnerability -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconVulnerability [-Filter] <String> [[-Facet] <String[]>] [[-Sort] <String>] [[-Limit] <Int32>] [-After <String>] -Detailed [-All] [-WhatIf] [-Confirm] [<CommonParameters>]

SDK Reference

falconpy

queryVulnerabilities
getVulnerabilities
combinedQueryVulnerabilities

USAGE

Search for vulnerabilities

NOTE: The Spotlight API requires the use of a filter when requesting results.

Get-FalconVulnerability -Filter "created_timestamp:>'2019-11-25T22:36:12Z'" [-Detailed] [-All]

Get information about specific vulnerabilities

Get-FalconVulnerability -Id <id>, <id>

2022-12-12: PSFalcon v2.2.3

Clone this wiki locally