Watch what is happening to your computers
CrowdStrike Falcon actions
Ask in plain language — Praxivara picks the right CrowdStrike Falcon action, runs it, and confirms anything sensitive first.
List Access Scopes By ID.
Shows query Access Scopes and returns IDs.
Shows retrieves aggregate values for Alerts across all CIDs.
Shows retrieves all Alerts that match a particular FQL.
Perform actions on detections identified.
Shows retrieves all Alerts given their composite ids.
Perform actions on Alerts identified by composite.
Shows retrieves all Alerts ids that match a given query.
Get all available scopes for customer.
Reset existing API Client(s)'s secret based on API.
Delete existing API Client(s) based on API Client.
Get API Client(s) based on API Client ID(s) provided.
Update existing API Client based on API Client ID.
Create new API Client.
Get All API client ID(s) for customer.
Search for hidden hosts in your environment.
Shows retrieve details about recent login sessions.
Shows retrieve details about recent interactive login.
Shows retrieve history of IP and MAC addresses of devices.
Search for hosts in your environment by platform.
Search for members of a Host Group in your.
Search for Host Groups in your environment.
Permanently delete hosts from the system.
Take various actions on the hosts in your environment.
Append or remove one or more Falcon Grouping Tags.
Get details on one or more hosts by providing agent.
Get details on one or more hosts by providing host.
Get details on one or more hosts by providing host.
Performs the specified action on the provided group.
Perform the specified action on the Host Groups.
Delete a set of Host Groups by specifying their IDs.
Shows retrieve a set of Host Groups by specifying their IDs.
Update Host Groups by specifying the ID of the group.
Create Host Groups by specifying details about.
Get the online status for one or more hosts.
Shows retrieve hidden hosts that match the provided filter.
Search for hosts in your environment by platform.
Search for hosts in your environment by platform.
Search for members of a Host Group in your.
Search for Host Groups in your environment.
Get exclusion aggregates as specified via json.
Get Self Service IOA Exclusion aggregates.
Get all exclusions.
Delete the exclusions by id.
Shows find all exclusion IDs matching the query with filter.
Updates existing Certificate Based Exclusions.
Create new Certificate Based Exclusions.
Shows retrieves certificate signing information for a file.
Actions used to manipulate the content.
Create a report of ML exclusions scoped by the given.
Delete the exclusions by id, with ancestor fields.
Get the exclusions by id, with ancestor fields.
Update the exclusions by id, with ancestor fields.
Create the exclusions, with ancestor fields.
Create a report of Self Service IOA Exclusions.
Delete the Self Service IOA Exclusions rule by id.
Get the Self Service IOA Exclusions rules by id.
Update the Self Service IOA Exclusions rule by id.
Create new Self Service IOA Exclusions.
Get Self Service IOA Exclusions rules for matched.
Get defaults for Self Service IOA Exclusions.
Search for cert-based exclusions.
Search for exclusions, with ancestor fields.
Search for Self Service IOA Exclusions.
Executes an SDMF data frame query against exclusion.
Shows download IOC packs, PCAP files, memory dumps.
Get extracted strings from a memory dump.
Get hex view of a memory dump.
Get memory dump content, as binary.
Get a short summary version of a sandbox report.
Delete report based on the report ID. Operation can.
Get a full sandbox report.
Check the status of a sandbox analysis.
Submit an uploaded file or a URL for sandbox analysis.
Shows find sandbox reports by providing an FQL filter.
Shows find submission IDs for uploaded files by providing.
Gets the details of one or more audit events by id.
Check current installation token settings.
Update installation token settings.
Deletes a token immediately.
Gets the details of one or more tokens by id.
Updates one or more tokens.
Creates a token.
Search for audit events by providing an FQL filter.
Search for tokens by providing an FQL filter.
Perform statistical aggregations over incident data.
Get info about actors that match provided FQL filters.
Get info about indicators that match provided FQL.
Get malware entities that match provided FQL filters.
Get info about reports that match provided FQL filters.
Shows retrieve specific actors using their actor IDs.
Shows retrieve full details for one or more adversary.
Shows retrieve specific indicators using their indicator IDs.
Shows export Mitre ATT&CK information for a given malware.
Get malware entities for specified ids.
Shows export Mitre ATT&CK information for a given actor.
Shows retrieves report and observable IDs associated.
Shows return a Report PDF attachment.
Shows retrieve specific reports using their report IDs.
Shows download earlier rule sets.
Shows download the latest rule set.
Shows retrieve details for rule sets for the specified ids.
Get vulnerabilities.
Get actor IDs that match provided FQL filters.
Search for adversary incidents using FQL criteria.
Get indicators IDs that match provided FQL filters.
Get malware family names that match provided FQL.
Gets MITRE tactics and techniques for the given.
Gets MITRE tactics and techniques for the given.
Get report IDs that match provided FQL filters.
Search for rule IDs that match provided filter.
Get vulnerabilities IDs.
Get the number of devices the indicator has run.
Get Indicators aggregates as specified via json.
Get Combined for Indicators.
Get Actions by ids.
Launch an indicators report creation job.
Delete Indicators by ids.
Get Indicators by ids.
Update Indicators.
Create Indicators.
Shows query Actions.
Get the IDs of devices the indicator has run.
Get the number of processes the indicator has run.
Search for Indicators.
Shows query IOC Types.
Shows query Platforms.
Shows query Severities.
Shows executes an SDMF data frame query against IOC.
Shows retrieve aggregate case values based on the matched.
Shows retrieve activities for given id's.
Add an activity to case.
Shows retrieves an attachment for the case, given.
Upload an attachment for the case.
create a new case.
Shows retrieve message center cases.
Shows retrieve activities id's for a case.
Shows retrieve case id's that match the provided filter.
Search for members of a Content Update Policy.
Search for Content Update Policies in your.
Search for members of a Device Control Policy.
Search for Device Control Policies in your.
Search for members of a Firewall Policy in your.
Search for Firewall Policies in your environment.
Shows increments a bulk maintenance token.
Search for members of a Prevention Policy in your.
Search for Prevention Policies in your environment.
Search for members of a Response policy in your.
Search for Response Policies in your environment.
Shows reveals an uninstall token for a specific device.
Shows retrieve available builds for use with Sensor Update.
Shows retrieve kernel compatibility info for Sensor Update.
Search for members of a Sensor Update Policy in your.
Search for Sensor Update Policies in your.
Search for Sensor Update Policies with additional.
Perform the specified action on the Content Update.
Sets the precedence of Content Update Policies.
Delete a set of Content Update Policies.
Shows retrieve a set of Content Update Policies.
Update Content Update Policies by specifying the ID.
Create Content Update Policies by specifying details.
Shows retrieve the configuration for a Default Device.
Update the configuration for a Default Device.
Perform the specified action on the Device Control.
Update device control policy's classes (USB.
Get default device control settings (USB.
Update the configuration for Default Device Control.
Sets the precedence of Device Control Policies.
Delete a set of Device Control Policies.
Shows retrieve a set of Device Control Policies.
Update Device Control Policies by specifying the ID.
Create Device Control Policies by specifying details.
Get device control policies for the given filter.
Update device control policy base (USB and Bluetooth).
Create/clone a device control policy (USB.
Perform the specified action on the Firewall.
Sets the precedence of Firewall Policies.
Delete a set of Firewall Policies by specifying.
Shows retrieve a set of Firewall Policies by specifying.
Update Firewall Policies by specifying the ID.
Create Firewall Policies by specifying details about.
Delete the IOA exclusions by id.
Get a set of IOA Exclusions by specifying their IDs.
Update the IOA exclusions.
Create the IOA exclusions.
Delete the ML exclusions by id.
Get a set of ML Exclusions by specifying their IDs.
Update the ML exclusions.
Create the ML exclusions.
Perform the specified action on the Prevention.
Sets the precedence of Prevention Policies.
Delete a set of Prevention Policies by specifying.
Shows retrieve a set of Prevention Policies by specifying.
Update Prevention Policies by specifying the ID.
Create Prevention Policies by specifying details.
Perform the specified action on the Response.
Sets the precedence of Response Policies.
Delete a set of Response Policies by specifying.
Shows retrieve a set of Response Policies by specifying.
Update Response Policies by specifying the ID.
Create Response Policies by specifying details about.
Perform the specified action on the Sensor Update.
Sets the precedence of Sensor Update Policies.
Delete a set of Sensor Update Policies by specifying.
Shows retrieve a set of Sensor Update Policies.
Update Sensor Update Policies by specifying the ID.
Create Sensor Update Policies by specifying details.
Shows retrieve a set of Sensor Update Policies.
Update Sensor Update Policies by specifying the ID.
Create Sensor Update Policies by specifying details.
Delete the sensor visibility exclusions by id.
Get a set of Sensor Visibility Exclusions.
Update the sensor visibility exclusions.
Create the sensor visibility exclusions.
Search for members of a Content Update Policy.
Search for content versions available for pinning.
Search for Content Update Policies in your.
Search for members of a Device Control Policy.
Search for Device Control Policies in your.
Search for members of a Firewall Policy in your.
Search for Firewall Policies in your environment.
Search for IOA exclusions.
Search for ML exclusions.
Search for members of a Prevention Policy in your.
Search for Prevention Policies in your environment.
Search for members of a Response policy in your.
Search for Response Policies in your environment.
Shows retrieve kernel compatibility info for Sensor Update.
Search for members of a Sensor Update Policy in your.
Search for Sensor Update Policies in your.
Search for sensor visibility exclusions.
Shows returns count of potentially affected quarantined.
Get quarantine file aggregates as specified via json.
Get quarantine file metadata for specified ids.
Apply action by quarantine file ids.
Get quarantine file ids that match the provided.
Apply quarantine file actions by query.
Get all the RTR sessions created for a customer.
Get aggregates on session data.
Shows batch executes a RTR active-responder command across.
Shows batch executes a RTR administrator command across.
Shows batch executes a RTR read-only command across.
Shows retrieves the status of the specified batch get.
Shows batch executes `get` command across hosts.
Shows batch initialize a RTR session on multiple hosts.
Shows batch refresh a RTR session on multiple hosts.
Get status of an executed active-responder command.
Execute an active responder command on a single host.
Get status of an executed RTR administrator command.
Execute a RTR administrator command on a single host.
Get status of an executed command on a single host.
Execute a command on a single host.
Get RTR extracted file contents for specified.
Get Falcon scripts with metadata and content of script.
Delete a RTR session file.
Get a list of files for the specified RTR session.
Delete a RTR session file.
Get a list of files for the specified RTR session.
Get RTR put file contents for a given file ID.
Delete a put-file based on the ID given.
Get put-files based on the ID's given.
Upload a new put-file to use for the RTR `put` command.
Get put-files based on the ID's given.
Upload a new put-file to use for the RTR `put` command.
Get queued session metadata by session ID.
Delete a queued session command.
Refresh a session timeout on a single host.
Delete a custom-script based on the ID given.
Get custom-scripts based on the ID's given.
Upload a new scripts to replace an existing one.
Upload a new custom-script to use for the RTR.
Get custom-scripts based on the ID's given.
Upload a new scripts to replace an existing one.
Upload a new custom-script to use for the RTR.
Get session metadata by session id.
Delete a session.
Initialize a new session with the RTR cloud.
Get a list of Falcon script IDs available.
Get a list of put-file ID's that are available.
Get a list of custom-script ID's that are available.
Get a list of session_ids.
Removes a sample, including file, meta.
Shows retrieves the file associated with the given ID.
Shows retrieves a list with sha256 of samples that exist.
Refresh an active event stream.
Shows discover all event streams in your environment.
Search for evaluation logic in your environment.
Shows performs a combined query and get operation.
Search for Vulnerabilities in your environment.
Shows performs a combined query and get operation.
Get details on evaluation logic items by providing.
Get details on remediations by providing one or more.
Get details on vulnerabilities by providing one.
Search for evaluation logic in your environment.
Search for Vulnerabilities in your environment.
Get event body for the provided event ID.
Get events entities for specified ids.
Get events ids that match the provided filter criteria.
Get rules entities for specified ids.
Get rules ids that match the provided filter criteria.
Get host aggregates as specified via json in request.
Get User Grant(s). This endpoint lists both direct.
Get info about a role.
Get info about a role.
Apply actions to one or more User.
Grant or Revoke one or more role(s) to a user.
Get info about users including their name, UID.
Delete a user permanently.
Modify an existing user's first or last name.
Create a new user.
Show role IDs for all roles available in your.
List user IDs for all users in your customer account.
Please use userRolesActionV1 Revoke one or more.
Shows please use entitiesRolesV1 Get info about a role.
Please use userRolesActionV1 Assign one or more.
Shows please use queriesRolesV1 Show role IDs for all.
Shows please use combinedUserRolesV1 Show role IDs.
Please use deleteUserV1 Delete a user permanently.
Shows please use retrieveUsersGETV1. Get info about a user.
Please use updateUserV1 Modify an existing user's.
Please use createUserV1 Create a new user.
Shows please use retrieveUsersGETV1 List the usernames.
Shows please use queryUserV1 List user IDs for all users.
Shows please use queryUserV1 Get a user's ID by providing.
Get Zero Trust Assessment data for one or more hosts.
Get the Zero Trust Assessment audit report for one.
Get Zero Trust Assessment data for one or more hosts.
CrowdStrike Falcon triggers
Events in CrowdStrike Falcon that can start an automation on their own — no clicks required once you set it up.
Checks CrowdStrike Falcon for alerts raised since the last run.
Watches hosts matching a filter and reports the ones whose state has changed.
What you can ask in plain English
No menus, no automation builder to learn. Type it like you'd ask a capable assistant — Praxivara figures out the CrowdStrike Falcon steps and shows you exactly what it did.
Related integrations
Let Praxivara run CrowdStrike Falcon for you.
Connect it in seconds and hand over the busywork — with you approving anything that matters. Start your 7-day free trial today.