Get FalconNgsCaseFile - CrowdStrike/psfalcon GitHub Wiki

Get-FalconNgsCaseFile

SYNOPSIS

Search for files in Falcon NGSIEM cases

DESCRIPTION

Requires 'Cases: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Case file identifier X X
Filter String Falcon Query Language expression to limit results
Limit Int32 Maximum number of results per request
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconNgsCaseFile [[-Filter] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconNgsCaseFile -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconNgsCaseFile [[-Filter] <String>] [[-Limit] <Int32>] [-Offset <Int32>] -Detailed [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /case-files/combined/file-details/v1
GET /case-files/entities/file-details/v1
GET /case-files/queries/file-details/v1

falconpy

queries_file_details_get_v1
entities_file_details_get_v1
combined_file_details_get_v1

USAGE

2025-08-11: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️