Edit FalconDetection - CrowdStrike/psfalcon GitHub Wiki
Modify detections
Requires 'Detections: Write'.
Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
---|---|---|---|---|---|---|---|
Comment | String | Detection comment | |||||
ShowInUi | Boolean | Visible within the Falcon UI [default: $true] | |||||
Status | String | Detection status |
new in_progress true_positive false_positive closed reopened
|
X | |||
AssignedToUuid | String | User identifier for assignment | X | ||||
Id | String[] | Detection identifier | X | X |
Edit-FalconDetection [[-Comment] <String>] [[-ShowInUi] <Boolean>] [[-Status] <String>] [[-AssignedToUuid] <String>] [-Id] <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
PATCH /detects/entities/detects/v2
NOTE: Edit-FalconDetection
will automatically group requests in batches of 1,000 detections (the API limit).
Edit-FalconDetection -Id <id>, <id> -Status new
WARNING: Hiding detections is not reversible!
Edit-FalconDetection -Id <id>, <id> -ShowInUi $false
See Hide detections involving a specific file.
2023-04-25: PSFalcon v2.2.5