Invoke FalconQuarantineAction - CrowdStrike/psfalcon Wiki

Invoke-FalconQuarantineAction

SYNOPSIS

Perform actions on quarantined files

DESCRIPTION

Requires 'Quarantined Files: Write'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Action String release
unrelease
delete
Action to perform
Filter String Falcon Query Language statement
Query String Match phrase prefix
Comment String Audit log comment
Id String[] X X Quarantined file identifier

SYNTAX

Invoke-FalconQuarantineAction [-Action] <String> [[-Comment] <String>] [-Id] <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Invoke-FalconQuarantineAction [-Action] <String> -Filter <String> [[-Query] <String>] [[-Comment] <String>] [-WhatIf] [-Confirm] [<CommonParameters>]

USAGE

2022-10-06: PSFalcon v2.2.3

⚠️ **GitHub.com Fallback** ⚠️