Receive FalconRule - CrowdStrike/psfalcon Wiki

Receive-FalconRule

SYNOPSIS

Download the most recent ruleset,or a specific ruleset

DESCRIPTION

Requires 'Rules (Falcon X): Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Type String snort-suricata-master
snort-suricata-update
snort-suricata-changelog
yara-master
yara-update
yara-changelog
common-event-format
netwitness
Ruleset type, used to retrieve the latest ruleset
Path String Destination path
Id Int32 X X Ruleset identifier, used for a specific ruleset
Force Switch Overwrite an existing file when present

SYNTAX

Receive-FalconRule [-Path] <String> [-Id] <Int32> [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
Receive-FalconRule [-Type] <String> [-Path] <String> [-WhatIf] [-Confirm] [<CommonParameters>]

Generated 20220922 using PSFalcon v2.2.3

⚠️ **GitHub.com Fallback** ⚠️