psfalcon
Cloud-AWS
Our great sponsors
psfalcon | Cloud-AWS | |
---|---|---|
169 | 18 | |
317 | 137 | |
2.8% | 0.7% | |
9.2 | 7.3 | |
6 days ago | 13 days ago | |
PowerShell | Python | |
The Unlicense | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
psfalcon
-
Migrate child cid to parent cid
Rather than using flight control, you could consider doing a import/export of your configuration, then mass uninstall and reinstall each individual existing CID into your new single CID. The parent would really only help with policy inheritence/detection rollup/rbac which you would no longer need after converting to a single instance.
-
Get Falcon Scanning Results Via API
Try using PSFalcon and Get-FalconDetection to see what's in a detection record.
- Filter issue with Get-FalconAsset
- Identity API for PSfalcon or FalconPY
-
Change sensor grouping tags via API
Add-FalconSensorTag Get-FalconSensorTag Remove-FalconSensorTag
- API for removing VDIs older than 24 hours
-
Create IOA Falconpy
There's an example of required fields under the New-FalconIoaRule wiki page, along with the values for disposition_id.
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
Status of API batch RTR commands when queued offline
Check out Get-FalconQueue. It goes through a few steps:
-
Invoke-FalconDeploy Behavior Change
Could you open an issue and include a PowerShell transcript with $VerbosePreference = 'Continue'?
Cloud-AWS
-
CS Sensor communication in AWS envirnoments
Nothing better than CrowdStrike and AWS!
-
CrowdStrike alternative to Kaspersky Scan Engine
You can find the sample here: https://github.com/CrowdStrike/Cloud-AWS/tree/main/s3-bucket-protection
- Best way to protect AWS EC2 instances with CrowdStrike, cloud posture?
-
Crowdstrike install with the terraform
We have an example bootstrap for AWS environments that leverages Terraform located here: https://github.com/CrowdStrike/Cloud-AWS/tree/main/Agent-Install-Examples/Terraform-bootstrap-s3
-
PSFalcon Documentation
Download and install Falcon using PowerShell (no PSFalcon required)
-
Installing Crowdstrike as Task Sequence Step in Endpoint Manager
I have my moments :) CrowdStrike actually do all the heavy lifting... https://github.com/CrowdStrike/Cloud-AWS/blob/main/Agent-Install-Examples/powershell/sensor_install.ps1
-
Is it possible to use PSFalcon to download and install the latest sensor?
Here's a bash version: https://github.com/CrowdStrike/Cloud-AWS/tree/main/Agent-Install-Examples/bash/API-download
-
What components are part of the "Falcon CWP for AWS" package?
Falcon sensor - sensor/agent is available as an EXE or container, or direct download over API (powershell example).
-
Using QuickScan API
Integration example: Protect a S3 bucket with CrowdStrike Quickscan
-
How do I create an unattended install with powershell?
MDM/Deployment tool of your choice + this example installer script = smooth sailing.
What are some alternatives?
falconpy - The CrowdStrike Falcon SDK for Python
CrowdStrike-Sensor-Download-and-Install - Script to automate the deployment of the latest CrowdStrike Falcon Sensor
swagger-ui - Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
Cloud-Azure - Discover for Cloud and Containers Azure
PowerFGT - PowerShell module to manage Fortinet (FortiGate) Firewall
rtr - Real-time Response scripts and schema
Cloud-GCP - A collection of projects supporting GCP integration
BulkStrike - BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
ansible_collection_falcon - Install and configure CrowdStrike's Falcon sensor via Ansible.
PSKoans - A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
Chocolatey - Chocolatey - the package manager for Windows