Get FalconBehavior - CrowdStrike/psfalcon GitHub Wiki

Get-FalconBehavior

SYNOPSIS

Search for behaviors

DESCRIPTION

Requires 'Incidents: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Behavior identifier X X
Filter String Falcon Query Language expression to limit results

aid
incident_id
pattern_id
template_instance_id
timestamp
Sort String Property and direction to sort results timestamp.asc
timestamp.desc
Limit Int32 Maximum number of results per request 1 500
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconBehavior [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconBehavior -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /incidents/queries/behaviors/v1
POST /incidents/entities/behaviors/GET/v1

falconpy

QueryBehaviors
GetBehaviors

USAGE

Find behaviors

Get-FalconBehavior [-Detailed] [-All]

2023-04-25: PSFalcon v2.2.5

⚠️ **GitHub.com Fallback** ⚠️