Get FalconQuarantine - CrowdStrike/psfalcon GitHub Wiki

Get-FalconQuarantine

SYNOPSIS

Search for quarantined files

DESCRIPTION

Requires 'Quarantined Files: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Quarantined file identifier X X
Filter String Falcon Query Language expression to limit results
Query String Match phrase prefix
Sort String Property and direction to sort results hostname.asc
hostname.desc
username.asc
username.desc
date_updated.asc
date_updated.desc
date_created.asc
date_created.desc
paths.path.asc
paths.path.desc
paths.state.asc
paths.state.desc
state.asc
state.desc
Limit Int32 Maximum number of results per request 1 5000
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconQuarantine [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconQuarantine -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /quarantine/queries/quarantined-files/v1
POST /quarantine/entities/quarantined-files/GET/v1

falconpy

QueryQuarantineFiles
GetQuarantineFiles

USAGE

Find quarantined files using a filtered search

Get-FalconQuarantine -Filter "device.hostname:'EXAMPLE-PC'"

Find information about specific quarantined files

Get-FalconQuarantine -Id <id>, <id>

2023-04-25: PSFalcon v2.2.5

⚠️ **GitHub.com Fallback** ⚠️