falconpy
psfalcon
falconpy | psfalcon | |
---|---|---|
30 | 169 | |
306 | 318 | |
1.6% | 1.3% | |
9.5 | 9.0 | |
10 days ago | 3 days ago | |
Python | PowerShell | |
The Unlicense | The Unlicense |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
falconpy
-
Identity API for PSfalcon or FalconPY
And for falconpy: https://github.com/CrowdStrike/falconpy/wiki/Identity-Protection
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
API - Group by Remediation
We also have an example that does some sorting and basic aggregation that's a little similar (but does not focus on remediations). Similar to your suggestion, this sample also consumes all available matches at the outset using a pretty expansive query.
-
How do i search for all hosts with FQL/FalconPy?
Here's a sample that will paginate through all of your hosts. Depending on the API call you're using, you can request up to 5,000 hosts.
-
Find Host by CVE List
Howdy Yall, qq. Does anyone know if it is possible to search not just one CVE but a short list? from the github here https://github.com/CrowdStrike/falconpy/blob/main/samples/spotlight/find_hosts_by_cve.py
-
Host and MSSP Endpoint’s
Logging in with the parent credentials to the Hosts Service Class will show hosts from child CIDs when you make calls to QueryDevicesByFilter or QueryDevicesByFilterScroll. For an example on how to paginate through the results, you can check out the sample here: https://github.com/CrowdStrike/falconpy/blob/main/samples/hosts/sensor_versions_by_hostname_scrolling.py
-
Help with simple python script
start with samples work backward: https://github.com/CrowdStrike/falconpy/tree/main/samples/hosts
-
How to Resolve a 405 Error When Setting Up CrowdStrike Stream with Google Chronicle?
I would need to see more of your code to get an idea for why you're running into this error. You may find it easier to review an existing integration that populates Chronicle via the Event Streams API instead. This one leverages our Python SDK: https://github.com/CrowdStrike/falcon-integration-gateway.
-
Associate Put file ID with put file name in Falconpy
Can I see more of your code? Feels like we're missing something. Sample code (queued execute): https://github.com/CrowdStrike/falconpy/blob/main/samples/rtr/queued_execute.py
-
Error when attempting to update Device Control policy
I think you may be right. It looks like the payload handler for this operation is not looking for the id key. (I will track this fix using the GitHub issue you just created. )
psfalcon
-
Migrate child cid to parent cid
Rather than using flight control, you could consider doing a import/export of your configuration, then mass uninstall and reinstall each individual existing CID into your new single CID. The parent would really only help with policy inheritence/detection rollup/rbac which you would no longer need after converting to a single instance.
-
Get Falcon Scanning Results Via API
Try using PSFalcon and Get-FalconDetection to see what's in a detection record.
- Filter issue with Get-FalconAsset
- Identity API for PSfalcon or FalconPY
-
Change sensor grouping tags via API
Add-FalconSensorTag Get-FalconSensorTag Remove-FalconSensorTag
- API for removing VDIs older than 24 hours
-
Create IOA Falconpy
There's an example of required fields under the New-FalconIoaRule wiki page, along with the values for disposition_id.
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
Status of API batch RTR commands when queued offline
Check out Get-FalconQueue. It goes through a few steps:
-
Invoke-FalconDeploy Behavior Change
Could you open an issue and include a PowerShell transcript with $VerbosePreference = 'Continue'?
What are some alternatives?
MISP-tools - Import CrowdStrike Threat Intelligence into your instance of MISP
swagger-ui - Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
BulkStrike - BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
PowerFGT - PowerShell module to manage Fortinet (FortiGate) Firewall
dotify - 🐍🎶 Yet another Spotify Web API Python library
rtr - Real-time Response scripts and schema
gybe - A simple YAML transpiler for rendering Kubernetes manifests using python type-hints.
gofalcon - Golang-based SDK to CrowdStrike's APIs
PSKoans - A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
msgraph-sdk-python-core - Microsoft Graph client library for Python
SnipeitPS - Powershell API Wrapper for Snipe-it