Invoke FalconPreventionPolicyAction - CrowdStrike/psfalcon GitHub Wiki
Perform actions on Prevention policies
Requires 'Prevention Policies: Write'.
| Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
|---|---|---|---|---|---|---|---|
| Name | String | Action to perform |
add-host-groupadd-rule-groupdisableenableremove-host-groupremove-rule-group
|
||||
| GroupId | String | Host or rule group identifier | |||||
| Id | String | Policy identifier | X | X |
Invoke-FalconPreventionPolicyAction [-Name] <String> [[-GroupId] <String>] [-Id] <String> [-WhatIf] [-Confirm] [<CommonParameters>]POST /policy/entities/prevention-actions/v1
performPreventionPoliciesAction
Invoke-FalconPreventionPolicyAction -Name add-host-group -Id <policy_id> -GroupId <host_group_id>Get-FalconPreventionPolicy -Filter "name:'my_policy'" | Invoke-FalconPreventionPolicyAction -Name add-host-group -GroupId <host_group_id>2023-04-25: PSFalcon v2.2.5
