Invoke FalconResponsePolicyAction - CrowdStrike/psfalcon GitHub Wiki
Perform actions on Real-time Response policies
Requires 'Response policies: Write'.
Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
---|---|---|---|---|---|---|---|
Name | String | Action to perform |
add-host-group disable enable remove-host-group
|
||||
GroupId | String | Host group identifier | |||||
Id | String | Policy identifier | X | X |
Invoke-FalconResponsePolicyAction [-Name] <String> [[-GroupId] <String>] [-Id] <String> [-WhatIf] [-Confirm] [<CommonParameters>]
POST /policy/entities/response-actions/v1
performRTResponsePoliciesAction
Invoke-FalconResponsePolicyAction -Name add-host-group -Id <id> -GroupId <id>
Invoke-FalconResponsePolicyAction -Name enable -Id <id>
2023-04-25: PSFalcon v2.2.5