psfalcon
gofalcon
Our great sponsors
psfalcon | gofalcon | |
---|---|---|
169 | 5 | |
317 | 51 | |
2.8% | - | |
9.2 | 8.2 | |
6 days ago | 3 days ago | |
PowerShell | Go | |
The Unlicense | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
psfalcon
-
Migrate child cid to parent cid
Rather than using flight control, you could consider doing a import/export of your configuration, then mass uninstall and reinstall each individual existing CID into your new single CID. The parent would really only help with policy inheritence/detection rollup/rbac which you would no longer need after converting to a single instance.
-
Get Falcon Scanning Results Via API
Try using PSFalcon and Get-FalconDetection to see what's in a detection record.
- Filter issue with Get-FalconAsset
- Identity API for PSfalcon or FalconPY
-
Change sensor grouping tags via API
Add-FalconSensorTag Get-FalconSensorTag Remove-FalconSensorTag
- API for removing VDIs older than 24 hours
-
Create IOA Falconpy
There's an example of required fields under the New-FalconIoaRule wiki page, along with the values for disposition_id.
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
Status of API batch RTR commands when queued offline
Check out Get-FalconQueue. It goes through a few steps:
-
Invoke-FalconDeploy Behavior Change
Could you open an issue and include a PowerShell transcript with $VerbosePreference = 'Continue'?
gofalcon
-
Several questions about CrowdStrike
Yes, using the Falcon APIs. Try PSFalcon, falconpy or gofalcon. Using PSFalcon, you could do this with the Invoke-FalconRtr command.
-
Modify Detections via API
I don't recommend using curl beyond testing. Why not try one of our API SDKs?
-
RTR API for files download
Go - GoFalcon
-
Crowdstrike API Help
CrowdStrike has more than one hundred different API endpoints, and they generally work in a handful of different ways. If you're new to APIs, it's easiest to start with a kit like falconpy, gofalcon or PSFalcon. These kits are all designed to help you handle the basic things like authentication, request formatting, pagination and even combining multiple APIs together to achieve a certain goal.
-
CrowdStrike API for Dummies?
PSFalcon makes these APIs easier to use with PowerShell, while falconpy and gofalcon make them easier to use with Python and Golang, respectively. If you're completely new to APIs but understand one of these languages, one of these tools will be the best place to start. If you'd like to pull this data directly with Excel, you're going to have to start from scratch, or figure out how you could use Excel to call one of these tools to get your data.
What are some alternatives?
falconpy - The CrowdStrike Falcon SDK for Python
swagger-ui - Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
PowerFGT - PowerShell module to manage Fortinet (FortiGate) Firewall
rtr - Real-time Response scripts and schema
BulkStrike - BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
PSKoans - A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
SnipeitPS - Powershell API Wrapper for Snipe-it
PSWinReporting - This PowerShell Module has multiple functionalities, but one of the signature features of this module is the ability to parse Security logs on Domain Controllers providing easy to use access to AD Events.
KaceSMA - A module for interacting with a Quest Kace Systems Management Appliance API via Powershell.
PSFalcon - PowerShell for CrowdStrike Falcon's OAuth2 APIs
CrowdStrike-Spotlight-Humio-Package-Integration